Payment Gateway Pix For GiveWP Security & Risk Analysis

wordpress.org/plugins/payment-gateway-pix-for-givewp

Add Pix Payment Gateway for GiveWP

100 active installs v2.2.4 PHP 7.4+ WP 6.0+ Updated Feb 18, 2026
gatewaygivegivewppaymentspix
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 28, 2026
Safety Verdict

Is Payment Gateway Pix For GiveWP Safe to Use in 2026?

Generally Safe

Score 99/100

Payment Gateway Pix For GiveWP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 28, 2026Updated 2mo ago
Risk Assessment

The plugin "payment-gateway-pix-for-givewp" v2.2.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has a very high rate of properly escaped output, minimizing cross-site scripting (XSS) risks. The absence of recorded vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase.

However, there are significant concerns related to the attack surface. The plugin exposes two AJAX handlers that lack authentication checks, presenting a direct pathway for unauthenticated users to interact with sensitive functionalities. While taint analysis and vulnerability history show no current issues, the lack of capability checks on these AJAX endpoints means that any user, regardless of their role, could potentially trigger these functions, leading to unintended consequences or information disclosure if not carefully implemented. The presence of external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the unprotected AJAX handlers.

Overall, the plugin has a good foundation with secure database interactions and output handling. The primary weakness lies in the unprotected AJAX endpoints, which represent a clear security gap. The vulnerability history is a positive sign, but the lack of authentication on entry points should be addressed to further strengthen its security.

Key Concerns

  • AJAX handlers without authentication checks
  • Entry points without authentication checks
  • Lack of capability checks on entry points
Vulnerabilities
1 published

Payment Gateway Pix For GiveWP Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-32425medium · 5.3Missing Authorization

Payment Gateway Pix For GiveWP <= 2.2.3 - Missing Authorization

Feb 28, 2026 Patched in 2.2.4 (47d)
Version History

Payment Gateway Pix For GiveWP Release Timeline

v2.2.4Current
v2.2.31 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.31 CVE
v2.0.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway Pix For GiveWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
67 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

97% escaped69 total outputs
Attack Surface
2 unprotected

Payment Gateway Pix For GiveWP Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_pgpf_pix_status_checkIncludes\PGPFGForGivewp.php:310
noprivwp_ajax_pgpf_pix_status_checkIncludes\PGPFGForGivewp.php:311

Shortcodes 1

[lkn_pgpf_give_paghiper_pix] Includes\PGPFGForGivewp.php:175
WordPress Hooks 14
actionplugins_loadedIncludes\PGPFGForGivewp.php:126
actionlkn_payment_pix_delete_old_logs_cron_hookIncludes\PGPFGForGivewp.php:162
actioninitIncludes\PGPFGForGivewp.php:276
filterplugin_row_metaIncludes\PGPFGForGivewp.php:279
actionadmin_enqueue_scriptsIncludes\PGPFGForGivewp.php:281
actionadmin_enqueue_scriptsIncludes\PGPFGForGivewp.php:282
filtercron_schedulesIncludes\PGPFGForGivewp.php:285
actioninitIncludes\PGPFGForGivewp.php:286
actioninitIncludes\PGPFGForGivewp.php:287
actiongivewp_register_payment_gatewayIncludes\PGPFGForGivewp.php:290
actiongive_get_settings_gatewaysIncludes\PGPFGForGivewp.php:292
actiongive_get_sections_gatewaysIncludes\PGPFGForGivewp.php:293
actionwp_enqueue_scriptsIncludes\PGPFGForGivewp.php:306
actionwp_enqueue_scriptsIncludes\PGPFGForGivewp.php:307

Scheduled Events 1

lkn_payment_pix_delete_old_logs_cron_hook
Maintenance & Trust

Payment Gateway Pix For GiveWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Payment Gateway Pix For GiveWP Developer Profile

linknacional

20 plugins · 7K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway Pix For GiveWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js
Script Paths
/wp-content/plugins/payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js
Version Parameters
payment-gateway-pix-for-givewp/admin/js/PGPFGForGivewpAdminSettings.js?ver=

HTML / DOM Fingerprints

JS Globals
PGPFGForGivewpAdminSettingsScript
FAQ

Frequently Asked Questions about Payment Gateway Pix For GiveWP