PixelPay ipg Security & Risk Analysis

wordpress.org/plugins/pixelpay-ipg

PixelPay Payment Gateway Plugin for WooCommerce

0 active installs v1.0.0 PHP 7.0+ WP 6.2+ Updated Jun 10, 2025
masternigeriasaved-cardsvervevisa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PixelPay ipg Safe to Use in 2026?

Generally Safe

Score 100/100

PixelPay ipg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'pixelpay-ipg' plugin version 1.0.0 exhibits a concerning security posture, primarily due to its unprotected entry points. While the plugin demonstrates good practices in terms of SQL query handling and avoids external HTTP requests, the presence of two AJAX handlers without any authentication or capability checks is a significant vulnerability. This means that any unauthenticated user could potentially trigger actions within these handlers, leading to unintended consequences. The absence of nonce checks further exacerbates this risk, as it opens the door to Cross-Site Request Forgery (CSRF) attacks. Furthermore, the fact that half of the output operations are not properly escaped suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, allowing malicious scripts to be injected and executed within the WordPress environment. The plugin's history of zero known CVEs is positive, but it does not mitigate the immediate risks identified in the static analysis. In conclusion, while the plugin avoids common pitfalls like raw SQL and bundled libraries, the lack of robust access control on its AJAX endpoints and potential XSS vulnerabilities represent critical security weaknesses that require immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks
  • Unescaped output
Vulnerabilities
None known

PixelPay ipg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PixelPay ipg Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

PixelPay ipg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface
2 unprotected

PixelPay ipg Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pixelpay_client_notepixelpay-ipg.php:117
noprivwp_ajax_pixelpay_client_notepixelpay-ipg.php:118
WordPress Hooks 13
actionwoocommerce_gateway_iconclasses\PixelPay_IPG_Gateway.php:41
actionwoocommerce_update_options_payment_gatewaysclasses\PixelPay_IPG_Gateway.php:46
actionadmin_noticespixelpay-ipg.php:28
actionplugins_loadedpixelpay-ipg.php:36
filterwoocommerce_payment_gatewayspixelpay-ipg.php:40
actionbefore_woocommerce_initpixelpay-ipg.php:65
actionwoocommerce_blocks_payment_method_type_registrationpixelpay-ipg.php:77
actionwoocommerce_blocks_loadedpixelpay-ipg.php:89
filterplugin_action_linkspixelpay-ipg.php:103
actionwp_footerpixelpay-ipg.php:127
actioninitpixelpay-ipg.php:225
actionadmin_enqueue_scriptspixelpay-ipg.php:227
actionwp_enqueue_scriptspixelpay-ipg.php:228
Maintenance & Trust

PixelPay ipg Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version7.0
Downloads199

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PixelPay ipg Developer Profile

pixelpaydevaccount

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PixelPay ipg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pixelpay-ipg/assets/css/admin-style.css/wp-content/plugins/pixelpay-ipg/assets/js/crypto-js.min.js
Script Paths
/wp-content/plugins/pixelpay-ipg/assets/js/crypto-js.min.js
Version Parameters
pixelpay-ipg/assets/css/admin-style.css?ver=pixelpay-ipg/assets/js/crypto-js.min.js?ver=

HTML / DOM Fingerprints

JS Globals
pp_msg
FAQ

Frequently Asked Questions about PixelPay ipg