Payment Gateway Pix For GiveWP Security & Risk Analysis

wordpress.org/plugins/payment-gateway-pix-for-givewp

Add Pix Payment Gateway for GiveWP

100 active installs v2.2.4 PHP 7.4+ WP 6.0+ Updated Feb 18, 2026
gatewaygivegivewppaymentspix
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway Pix For GiveWP Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway Pix For GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "payment-gateway-pix-for-givewp" v2.2.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has a very high rate of properly escaped output, minimizing cross-site scripting (XSS) risks. The absence of recorded vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase.

However, there are significant concerns related to the attack surface. The plugin exposes two AJAX handlers that lack authentication checks, presenting a direct pathway for unauthenticated users to interact with sensitive functionalities. While taint analysis and vulnerability history show no current issues, the lack of capability checks on these AJAX endpoints means that any user, regardless of their role, could potentially trigger these functions, leading to unintended consequences or information disclosure if not carefully implemented. The presence of external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the unprotected AJAX handlers.

Overall, the plugin has a good foundation with secure database interactions and output handling. The primary weakness lies in the unprotected AJAX endpoints, which represent a clear security gap. The vulnerability history is a positive sign, but the lack of authentication on entry points should be addressed to further strengthen its security.

Key Concerns

  • AJAX handlers without authentication checks
  • Entry points without authentication checks
  • Lack of capability checks on entry points
Vulnerabilities
None known

Payment Gateway Pix For GiveWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway Pix For GiveWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
67 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

97% escaped69 total outputs
Attack Surface
2 unprotected

Payment Gateway Pix For GiveWP Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_pgpf_pix_status_checkIncludes\PGPFGForGivewp.php:310
noprivwp_ajax_pgpf_pix_status_checkIncludes\PGPFGForGivewp.php:311

Shortcodes 1

[lkn_pgpf_give_paghiper_pix] Includes\PGPFGForGivewp.php:175
WordPress Hooks 14
actionplugins_loadedIncludes\PGPFGForGivewp.php:126
actionlkn_payment_pix_delete_old_logs_cron_hookIncludes\PGPFGForGivewp.php:162
actioninitIncludes\PGPFGForGivewp.php:276
filterplugin_row_metaIncludes\PGPFGForGivewp.php:279
actionadmin_enqueue_scriptsIncludes\PGPFGForGivewp.php:281
actionadmin_enqueue_scriptsIncludes\PGPFGForGivewp.php:282
filtercron_schedulesIncludes\PGPFGForGivewp.php:285
actioninitIncludes\PGPFGForGivewp.php:286
actioninitIncludes\PGPFGForGivewp.php:287
actiongivewp_register_payment_gatewayIncludes\PGPFGForGivewp.php:290
actiongive_get_settings_gatewaysIncludes\PGPFGForGivewp.php:292
actiongive_get_sections_gatewaysIncludes\PGPFGForGivewp.php:293
actionwp_enqueue_scriptsIncludes\PGPFGForGivewp.php:306
actionwp_enqueue_scriptsIncludes\PGPFGForGivewp.php:307

Scheduled Events 1

lkn_payment_pix_delete_old_logs_cron_hook
Maintenance & Trust

Payment Gateway Pix For GiveWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Payment Gateway Pix For GiveWP Developer Profile

linknacional

18 plugins · 5K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway Pix For GiveWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js
Script Paths
/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js
Version Parameters
payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js?ver=

HTML / DOM Fingerprints

JS Globals
PGPFGForGivewpAdminSettingsScript
FAQ

Frequently Asked Questions about Payment Gateway Pix For GiveWP