
PayEx WooCommerce Payments Security & Risk Analysis
wordpress.org/plugins/payex-woocommerce-paymentsThis plugin provides the PayEx Payment Gateway for WooCommerce.
Is PayEx WooCommerce Payments Safe to Use in 2026?
Generally Safe
Score 85/100PayEx WooCommerce Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "payex-woocommerce-payments" plugin version 1.3.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids external HTTP requests. The absence of known CVEs and a clean vulnerability history suggest a generally stable codebase. However, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without authentication checks represents a clear vulnerability. While taint analysis did not reveal critical or high severity issues, the two identified flows with unsanitized paths are concerning and warrant investigation, especially when combined with the unprotected AJAX endpoints. The plugin also has a moderate number of output operations, with a notable percentage (29%) not being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The limited number of nonce and capability checks further contributes to the risk.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths
- Unescaped output instances
- Limited nonce checks
- Limited capability checks
PayEx WooCommerce Payments Security Vulnerabilities
PayEx WooCommerce Payments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PayEx WooCommerce Payments Attack Surface
AJAX Handlers 4
WordPress Hooks 35
Maintenance & Trust
PayEx WooCommerce Payments Maintenance & Trust
Maintenance Signals
Community Trust
PayEx WooCommerce Payments Alternatives
Braintree for WooCommerce Payment Gateway
woocommerce-gateway-paypal-powered-by-braintree
Accept PayPal, Credit Cards, and Debit Cards on your WooCommerce store.
dLocal Go Payments
dlocal-go-payments-for-woocommerce
Accept dLocal Go payment methods in your WooCommerce store.
PayPal Checkout Payment for WooCommerce in Japan
pp-express-wc4jp
Accept PayPal, Credit Cards and Debit Cards on your WooCommerce store.
Slim CD payment gateway
slimcd-payment-gateway
Accept credit card/check payments for woocommerce stores, using your own merchant account.
AstroPay for WooCommerce
astropay-for-woocommerce
Accept AstroPay payment methods in your WooCommerce store.
PayEx WooCommerce Payments Developer Profile
3 plugins · 320 total installs
How We Detect PayEx WooCommerce Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payex-woocommerce-payments/assets/css/payex-admin.css/wp-content/plugins/payex-woocommerce-payments/assets/js/payex-admin.js/wp-content/plugins/payex-woocommerce-payments/assets/js/payex-admin.jspayex-woocommerce-payments/assets/css/payex-admin.css?ver=payex-woocommerce-payments/assets/js/payex-admin.js?ver=HTML / DOM Fingerprints
wc-payex-admin-field<!-- PayEx Payment Details --><!-- PayEx transactions -->data-payex-gateway