
Nexi XPay Build Security & Risk Analysis
wordpress.org/plugins/nexi-xpay-buildXPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
Is Nexi XPay Build Safe to Use in 2026?
Generally Safe
Score 100/100Nexi XPay Build has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nexi-xpay-build" v7.6.2 plugin exhibits a significant security concern due to a large, unprotected attack surface. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and avoids dangerous functions, its implementation of AJAX handlers and REST API routes is highly insecure. A concerning 12 out of 13 total entry points lack authentication or permission checks, exposing them to potential unauthorized access and manipulation. Furthermore, the low percentage of properly escaped output suggests a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data may be rendered without sufficient sanitization.
The plugin's taint analysis indicates one flow with unsanitized paths, although it was not classified as critical or high severity. This, combined with the absence of any recorded vulnerabilities (CVEs) and lack of nonce checks, might suggest that current exploit vectors are limited or undiscovered. However, the fundamental weaknesses in its access control for entry points present a broad and easily exploitable attack surface that could be leveraged in conjunction with other, potentially subtle, vulnerabilities. The plugin's strengths lie in its database query security and lack of known historical exploits, but its extensive unprotected entry points and poor output escaping are critical security deficiencies that need immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Low percentage of properly escaped output
- Flow with unsanitized paths (taint analysis)
- No nonce checks
Nexi XPay Build Security Vulnerabilities
Nexi XPay Build Code Analysis
Output Escaping
Data Flow Analysis
Nexi XPay Build Attack Surface
AJAX Handlers 6
REST API Routes 7
WordPress Hooks 30
Scheduled Events 2
Maintenance & Trust
Nexi XPay Build Maintenance & Trust
Maintenance Signals
Community Trust
Nexi XPay Build Alternatives
Nexi XPay
cartasi-x-pay
XPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
Instamojo for WooCommerce
woo-instamojo
Sell & collect payments instantly for almost anything -- directly from your WordPress website.
Up2pay e-Transactions WooCommerce Payment Gateway
e-transactions-wc
This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x
HyperPay Payments
hyperpay-gateways
Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.
Paybox WooCommerce Payment Gateway
paybox-woocommerce-gateway
This plugin is a Paybox payment gateway for WooCommerce 4.x
Nexi XPay Build Developer Profile
2 plugins · 6K total installs
How We Detect Nexi XPay Build
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nexi-xpay-build/assets/js/xpay-build-npg.js/wp-content/plugins/nexi-xpay-build/assets/js/xpay-build.js/wp-content/plugins/nexi-xpay-build/assets/js/xpay.js/wp-content/plugins/nexi-xpay-build/assets/css/xpay.cssassets/js/xpay.jsassets/js/xpay-build-npg.jsassets/js/xpay-build.jsnexi-xpay-build/assets/js/xpay.js?ver=nexi-xpay-build/assets/css/xpay.css?ver=nexi-xpay-build/assets/js/xpay-build-npg.js?ver=nexi-xpay-build/assets/js/xpay-build.js?ver=HTML / DOM Fingerprints
data-payment-method="xpay_build"window.Nexi_Xpay_Build_Params/wp-json/nexi/v1/s2s/xpay/wp-json/nexi/v1/s2s/npg