OpenPix for WooCommerce Security & Risk Analysis

wordpress.org/plugins/openpix-for-woocommerce

Accept Pix payments with real-time updates and seamless checkout.

600 active installs v2.13.7 PHP 7.3+ WP 4.0+ Updated Feb 18, 2026
openpixpaymentpixwoocommerce
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 11, 2026
Download
Safety Verdict

Is OpenPix for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

OpenPix for WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Feb 11, 2026Updated 1mo ago
Risk Assessment

The static analysis of "openpix-for-woocommerce" v2.13.7 reveals a generally positive security posture with several good practices in place. The plugin demonstrates a strong adherence to secure coding by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on all its identified AJAX entry points. The absence of any critical or high-severity taint flows further suggests that sensitive data is being handled with a reasonable degree of caution. However, there are areas for improvement. The output escaping is only properly implemented for 65% of outputs, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.

The vulnerability history is a significant concern. The plugin has a known CVE, which is currently unpatched and categorized as medium severity. This indicates a persistent security flaw that has not been addressed, potentially exposing users to risk. The fact that the last vulnerability was recorded in the future (2026-02-11) is likely a data entry error but still highlights a recent (or potentially ongoing) issue that needs attention. While the plugin has strengths in its input validation and use of prepared statements, the presence of an unpatched medium-severity vulnerability and incomplete output escaping necessitate caution and prompt remediation.

Key Concerns

  • Unpatched medium severity CVE
  • Incomplete output escaping
Vulnerabilities
1

OpenPix for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-15400medium · 4.3Missing Authorization

OpenPix <= 2.13.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Feb 11, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

OpenPix for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
50
94 escaped
Nonce Checks
3
Capability Checks
3
File Operations
5
External Requests
14
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

65% escaped144 total outputs
Attack Surface

OpenPix for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_openpix_crediary_prepare_oneclickincludes\class-wc-openpix-pix-crediary.php:42
authwp_ajax_openpix_parcelado_prepare_oneclickincludes\class-wc-openpix-pix-parcelado.php:40
authwp_ajax_openpix_prepare_oneclickincludes\class-wc-openpix-pix.php:39
WordPress Hooks 23
actionadmin_footerincludes\class-wc-openpix-boleto.php:38
actionwoocommerce_view_orderincludes\class-wc-openpix-boleto.php:115
actionwoocommerce_after_order_detailsincludes\class-wc-openpix-boleto.php:117
actionwoocommerce_api_wc_openpix_boleto_gatewayincludes\class-wc-openpix-boleto.php:122
actionadmin_footerincludes\class-wc-openpix-pix-crediary.php:9
actionwoocommerce_api_wc_openpix_pix_crediary_gatewayincludes\class-wc-openpix-pix-crediary.php:108
actionwoocommerce_after_order_detailsincludes\class-wc-openpix-pix-crediary.php:117
actionadmin_footerincludes\class-wc-openpix-pix-parcelado.php:9
actionwoocommerce_api_wc_openpix_pix_parcelado_gatewayincludes\class-wc-openpix-pix-parcelado.php:109
actionwoocommerce_after_order_detailsincludes\class-wc-openpix-pix-parcelado.php:118
actionadmin_footerincludes\class-wc-openpix-pix.php:9
actionwoocommerce_api_wc_openpix_pix_gatewayincludes\class-wc-openpix-pix.php:114
actionwoocommerce_after_order_detailsincludes\class-wc-openpix-pix.php:123
actionwoocommerce_openpix_pix_emailincludes\class-wc-openpix-pix.php:128
actionbefore_woocommerce_initopenpix-for-woocommerce.php:34
actionplugins_loadedopenpix-for-woocommerce.php:53
filterwoocommerce_payment_gatewaysopenpix-for-woocommerce.php:80
actionwp_enqueue_scriptsopenpix-for-woocommerce.php:81
actionwoocommerce_blocks_loadedopenpix-for-woocommerce.php:82
filteroption_woocommerce_gateway_orderopenpix-for-woocommerce.php:84
actionwoocommerce_before_checkout_formopenpix-for-woocommerce.php:90
actionadmin_noticesopenpix-for-woocommerce.php:94
actionwoocommerce_blocks_payment_method_type_registrationopenpix-for-woocommerce.php:216
Maintenance & Trust

OpenPix for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.3
Downloads21K

Community Trust

Rating100/100
Number of ratings5
Active installs600
Developer Profile

OpenPix for WooCommerce Developer Profile

sibeliusseraphini

1 plugin · 600 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OpenPix for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_boleto.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_boleto.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_pix_parcelado.css/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_crediary.js/wp-content/plugins/openpix-for-woocommerce/assets/css/openpix_pix_crediary.css
Script Paths
/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_boleto.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js/wp-content/plugins/openpix-for-woocommerce/assets/js/openpix_pix_crediary.js
Version Parameters
openpix-for-woocommerce/assets/js/openpix.js?ver=openpix-for-woocommerce/assets/css/openpix.css?ver=openpix-for-woocommerce/assets/js/openpix_boleto.js?ver=openpix-for-woocommerce/assets/css/openpix_boleto.css?ver=openpix-for-woocommerce/assets/js/openpix_pix_parcelado.js?ver=openpix-for-woocommerce/assets/css/openpix_pix_parcelado.css?ver=openpix-for-woocommerce/assets/js/openpix_pix_crediary.js?ver=openpix-for-woocommerce/assets/css/openpix_pix_crediary.css?ver=

HTML / DOM Fingerprints

CSS Classes
openpix-pix-gateway-containeropenpix-pix-parcelado-gateway-containeropenpix-pix-crediary-gateway-containeropenpix-boleto-gateway-containeropenpix-qr-code-containeropenpix-payment-infoopenpix-payment-status
HTML Comments
<!-- OpenPix Pix Gateway Settings --><!-- OpenPix Pix Parcelado Gateway Settings --><!-- OpenPix Pix Crediary Gateway Settings --><!-- OpenPix Boleto Gateway Settings -->+2 more
Data Attributes
data-openpix-pix-iddata-openpix-pix-amountdata-openpix-pix-qrcodedata-openpix-payment-status-urldata-openpix-order-id
JS Globals
openpix_pix_paramsopenpix_boleto_paramsopenpix_pix_parcelado_paramsopenpix_pix_crediary_paramsopenpixPaymentStatusChecker
REST Endpoints
/wp-json/openpix/v1/pix/qrcode/wp-json/openpix/v1/pix/status/wp-json/openpix/v1/boleto/qrcode/wp-json/openpix/v1/boleto/status
Shortcode Output
[openpix_pix_qrcode][openpix_boleto_barcode][openpix_payment_status]
FAQ

Frequently Asked Questions about OpenPix for WooCommerce