OxaPay Crypto Payment Gateway for Paid Memberships Pro Security & Risk Analysis

wordpress.org/plugins/oxapay-crypto-gateway-for-paid-memberships-pro

Accept cryptocurrency payments in Paid Memberships Pro using a secure and reliable gateway.

0 active installs v1.0.0 PHP 7.0+ WP 6.7+ Updated Dec 20, 2025
bitcoin-payment-gatewaybitcoin-paymentscrypto-payment-gatewaycrypto-paymentsoxapay
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OxaPay Crypto Payment Gateway for Paid Memberships Pro Safe to Use in 2026?

Generally Safe

Score 100/100

OxaPay Crypto Payment Gateway for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of "oxapay-crypto-gateway-for-paid-memberships-pro" v1.0.0 reveals a generally positive security posture with some areas for improvement. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. The absence of dangerous functions and the minimal file operations are also encouraging. However, the lack of any nonce checks or capability checks on entry points is a significant concern. While the current attack surface appears to be zero, this absence of authorization checks means that if any entry points were to be introduced or discovered in the future, they would likely be unprotected.

The taint analysis shows two flows with unsanitized paths, which, while not classified as critical or high severity in this report, warrant careful investigation. These could represent potential vulnerabilities if an attacker can influence the data flowing through these paths. The plugin's history of zero known CVEs is a strong indicator of responsible development and a lack of publicly disclosed vulnerabilities, which is a significant strength. However, the absence of any vulnerability history does not guarantee future security, especially given the identified gaps in authorization checks.

In conclusion, the plugin exhibits strengths in its handling of database queries and output sanitization, and its vulnerability-free history is commendable. Nevertheless, the complete absence of nonce and capability checks, combined with the identified unsanitized taint flows, presents potential risks. Future development should prioritize implementing robust authorization mechanisms to mitigate these concerns.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Taint flow with unsanitized path (x2)
Vulnerabilities
None known

OxaPay Crypto Payment Gateway for Paid Memberships Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OxaPay Crypto Payment Gateway for Paid Memberships Pro Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

OxaPay Crypto Payment Gateway for Paid Memberships Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_settings_fields (oxapay-crypto-gateway-for-paid-memberships-pro.php:261)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OxaPay Crypto Payment Gateway for Paid Memberships Pro Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitoxapay-crypto-gateway-for-paid-memberships-pro.php:22
filterpmpro_gatewaysoxapay-crypto-gateway-for-paid-memberships-pro.php:33
filterpmpro_payment_optionsoxapay-crypto-gateway-for-paid-memberships-pro.php:35
filterpmpro_payment_option_fieldsoxapay-crypto-gateway-for-paid-memberships-pro.php:37
filterpmpro_include_billing_address_fieldsoxapay-crypto-gateway-for-paid-memberships-pro.php:42
filterpmpro_include_payment_information_fieldsoxapay-crypto-gateway-for-paid-memberships-pro.php:43
filterpmpro_required_billing_fieldsoxapay-crypto-gateway-for-paid-memberships-pro.php:44
Maintenance & Trust

OxaPay Crypto Payment Gateway for Paid Memberships Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 20, 2025
PHP min version7.0
Downloads375

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

OxaPay Crypto Payment Gateway for Paid Memberships Pro Developer Profile

OxaPay

5 plugins · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OxaPay Crypto Payment Gateway for Paid Memberships Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/oxapay-crypto-gateway-for-paid-memberships-pro/js/oxapay-pmpro.js
Version Parameters
oxapay-crypto-gateway-for-paid-memberships-pro/js/oxapay-pmpro.js?ver=

HTML / DOM Fingerprints

CSS Classes
oxapay_gatewaygateway_oxapay
HTML Comments
<!-- OxaPay Settings Section --><!-- Merchant Key --><!-- Lifetime --><!-- Sandbox -->
Data Attributes
id="oxapay_merchant_id"name="oxapay_merchant_id"id="oxapay_lifetime"name="oxapay_lifetime"id="oxapay_sandbox"name="oxapay_sandbox"
FAQ

Frequently Asked Questions about OxaPay Crypto Payment Gateway for Paid Memberships Pro