IN4X Crypto Payment Security & Risk Analysis

wordpress.org/plugins/in4x-crypto-payment

Increase your customers base by accepting cryptocurrencies.

0 active installs v1.0.4 PHP 5.6+ WP 4.6+ Updated Apr 20, 2022
automatic-cryptocurrency-exchangecrypto-paymentscryptocurrency-payment-gatewayusdcusdt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IN4X Crypto Payment Safe to Use in 2026?

Generally Safe

Score 85/100

IN4X Crypto Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The security posture of the 'in4x-crypto-payment' plugin v1.0.4 appears to be generally good based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with potential unprotected entry points is a positive indicator. Furthermore, the code signals show no dangerous functions and all SQL queries utilize prepared statements, which significantly mitigates the risk of SQL injection vulnerabilities. The vulnerability history also indicates a clean record with no known CVEs, suggesting a consistent effort towards security by the developers.

However, there are some areas that warrant attention. The output escaping is only at 40% proper, meaning a significant portion of output might be susceptible to cross-site scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests, while not inherently problematic, can introduce risks if not handled with extreme care and proper sanitization. Crucially, the lack of nonce checks and capability checks across all identified entry points is a significant concern. This absence means that any potential, even if currently unexposed, entry points could be exploited without proper authorization or session verification.

In conclusion, while the plugin benefits from a lack of known vulnerabilities and secure database practices, the insufficient output escaping and, more importantly, the absence of authorization checks in code signals represent notable weaknesses. These could be exploited if any new attack vectors are introduced or if the plugin's limited attack surface were to expand in future versions. Continuous vigilance regarding output sanitization and the implementation of robust authorization checks are recommended.

Key Concerns

  • Output escaping is only 40% proper
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

IN4X Crypto Payment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

IN4X Crypto Payment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Attack Surface

IN4X Crypto Payment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadednx-payment.php:53
actionwoocommerce_api_nx_paymentnx-payment.php:103
filterwoocommerce_payment_gatewaysnx-payment.php:387
Maintenance & Trust

IN4X Crypto Payment Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 20, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

IN4X Crypto Payment Developer Profile

Alexander Sayegh

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IN4X Crypto Payment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/in4x-crypto-payment/nx-style.css/wp-content/plugins/in4x-crypto-payment/nx-gtag.js
Script Paths
/app/widget/in4x-widget.js/app/widget/in4x-widget.css
Version Parameters
in4x-crypto-payment/nx-style.css?ver=in4x-crypto-payment/nx-gtag.js?ver=in4x-crypto-payment/nx-script.js?ver=

HTML / DOM Fingerprints

JS Globals
nx_payment_params
REST Endpoints
/wp-json/nx_payment
FAQ

Frequently Asked Questions about IN4X Crypto Payment