
OpenPix for WooCommerce Security & Risk Analysis
wordpress.org/plugins/openpix-for-woocommerceAccept Pix payments with real-time updates and seamless checkout.
Is OpenPix for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 78/100OpenPix for WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of "openpix-for-woocommerce" v2.13.7 reveals a generally positive security posture with several good practices in place. The plugin demonstrates a strong adherence to secure coding by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on all its identified AJAX entry points. The absence of any critical or high-severity taint flows further suggests that sensitive data is being handled with a reasonable degree of caution. However, there are areas for improvement. The output escaping is only properly implemented for 65% of outputs, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
The vulnerability history is a significant concern. The plugin has a known CVE, which is currently unpatched and categorized as medium severity. This indicates a persistent security flaw that has not been addressed, potentially exposing users to risk. The fact that the last vulnerability was recorded in the future (2026-02-11) is likely a data entry error but still highlights a recent (or potentially ongoing) issue that needs attention. While the plugin has strengths in its input validation and use of prepared statements, the presence of an unpatched medium-severity vulnerability and incomplete output escaping necessitate caution and prompt remediation.
Key Concerns
- Unpatched medium severity CVE
- Incomplete output escaping
OpenPix for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
OpenPix <= 2.13.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update
OpenPix for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
OpenPix for WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 23
Maintenance & Trust
OpenPix for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
OpenPix for WooCommerce Alternatives
Pix por Piggly (para Woocommerce)
pix-por-piggly
Pix por Piggly v2.1.2
Pix Automático com Pagarme para WooCommerce
wc-pagarme-pix-payment
Pagamentos Pix com compensação automática, status do pedido é alterado automaticamente.
Efí Bank
woo-gerencianet-official
Receba pagamentos por Boleto bancário, Pix, Cartão de Crédito, Open Finance, Assinaturas via Boleto e/ou Cartão de Crédito em sua loja WooCommerce com …
WP28 Pague com Pix
wp28-pague-com-pix
Add Pix as WooCommerce payment method. Adiciona ao WooCommerce o método de pagamento Pix
Parcelow
parcelow
Payment method that can be easily integrated
OpenPix for WooCommerce Developer Profile
1 plugin · 600 total installs
How We Detect OpenPix for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_boleto.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_boleto.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_pix_parcelado.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_crediary.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_pix_crediary.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_boleto.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_crediary.jsopenpix-for-woocommerce/assets/js/openpix.js?ver=openpix-for-woocommerce/assets/css/openpix.css?ver=openpix-for-woocommerce/assets/js/openpix_boleto.js?ver=openpix-for-woocommerce/assets/css/openpix_boleto.css?ver=openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js?ver=openpix-for-woocommerce/assets/css/openpix_pix_parcelado.css?ver=openpix-for-woocommerce/assets/js/openpix_pix_crediary.js?ver=openpix-for-woocommerce/assets/css/openpix_pix_crediary.css?ver=HTML / DOM Fingerprints
openpix-pix-gateway-containeropenpix-pix-parcelado-gateway-containeropenpix-pix-crediary-gateway-containeropenpix-boleto-gateway-containeropenpix-qr-code-containeropenpix-payment-infoopenpix-payment-status<!-- OpenPix Pix Gateway Settings --><!-- OpenPix Pix Parcelado Gateway Settings --><!-- OpenPix Pix Crediary Gateway Settings --><!-- OpenPix Boleto Gateway Settings -->+2 moredata-openpix-pix-iddata-openpix-pix-amountdata-openpix-pix-qrcodedata-openpix-payment-status-urldata-openpix-order-idopenpix_pix_paramsopenpix_boleto_paramsopenpix_pix_parcelado_paramsopenpix_pix_crediary_paramsopenpixPaymentStatusChecker/wp-json/openpix/v1/pix/qrcode/wp-json/openpix/v1/pix/status/wp-json/openpix/v1/boleto/qrcode/wp-json/openpix/v1/boleto/status[openpix_pix_qrcode][openpix_boleto_barcode][openpix_payment_status]