
Payment Gateway Pix For GiveWP Security & Risk Analysis
wordpress.org/plugins/payment-gateway-pix-for-givewpAdd Pix Payment Gateway for GiveWP
Is Payment Gateway Pix For GiveWP Safe to Use in 2026?
Generally Safe
Score 100/100Payment Gateway Pix For GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "payment-gateway-pix-for-givewp" v2.2.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has a very high rate of properly escaped output, minimizing cross-site scripting (XSS) risks. The absence of recorded vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase.
However, there are significant concerns related to the attack surface. The plugin exposes two AJAX handlers that lack authentication checks, presenting a direct pathway for unauthenticated users to interact with sensitive functionalities. While taint analysis and vulnerability history show no current issues, the lack of capability checks on these AJAX endpoints means that any user, regardless of their role, could potentially trigger these functions, leading to unintended consequences or information disclosure if not carefully implemented. The presence of external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the unprotected AJAX handlers.
Overall, the plugin has a good foundation with secure database interactions and output handling. The primary weakness lies in the unprotected AJAX endpoints, which represent a clear security gap. The vulnerability history is a positive sign, but the lack of authentication on entry points should be addressed to further strengthen its security.
Key Concerns
- AJAX handlers without authentication checks
- Entry points without authentication checks
- Lack of capability checks on entry points
Payment Gateway Pix For GiveWP Security Vulnerabilities
Payment Gateway Pix For GiveWP Code Analysis
Output Escaping
Payment Gateway Pix For GiveWP Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Payment Gateway Pix For GiveWP Maintenance & Trust
Maintenance Signals
Community Trust
Payment Gateway Pix For GiveWP Alternatives
WPExperts Square For GiveWP
wpexperts-square-for-give
GiveWP Square plugin for WordPress allows users to donate from their give-donation form using Square payment gateway. Now, you can accept credit card …
LSX PayFast Gateway for Give
lsx-give-payfast-gateway
PayFast payment gateway for Give.
Bitcoin payment for GiveWP
coinsnap-for-givewp
Receive Bitcoin donations or Bitcoin contributions for your fundraisers. Easy setup, fast & simple transactions.
LinkNacional Multi Currency for GiveWP
lknaci-multi-currency-for-givewp
Transform your GiveWP donation forms with seamless multi-currency support and real-time exchange rates.
Payment Gateway GiveWP Asoriba BusinessPay
payment-gateway-givewp-asoriba-businesspay
BusinessPay is a Ghanaian Payment Gateway Add-on for the GiveWP plugin.
Payment Gateway Pix For GiveWP Developer Profile
18 plugins · 5K total installs
How We Detect Payment Gateway Pix For GiveWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.jspayment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js?ver=HTML / DOM Fingerprints
PGPFGForGivewpAdminSettingsScript