
uPlexa WooCommerce Extension Security & Risk Analysis
wordpress.org/plugins/uplexa-woocommerce-gatewayuPlexa WooCommerce Extension is a Wordpress plugin that allows to accept bitcoins at WooCommerce-powered online stores.
Is uPlexa WooCommerce Extension Safe to Use in 2026?
Generally Safe
Score 85/100uPlexa WooCommerce Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "uplexa-woocommerce-gateway" plugin v1.0.0 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) in its history, and the static analysis reveals no critical or high severity taint flows. The vast majority of SQL queries utilize prepared statements, and there are no bundled libraries that could introduce outdated components. The total attack surface is relatively small, with no immediate AJAX handlers or REST API routes identified as unprotected. However, several areas raise significant concerns. The complete absence of nonce checks and capability checks is a major weakness, leaving potential entry points vulnerable to CSRF attacks and privilege escalation if any of the entry points were to be exploited or extended in the future. Furthermore, the low percentage of properly escaped output (22%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without adequate sanitization. The plugin also performs external HTTP requests, which, without proper validation or sanitization of the requested URLs or returned data, could lead to SSRF vulnerabilities or the execution of malicious code. The limited analysis of taint flows might also be due to the analysis tool's limitations or the specific code structure, and doesn't entirely negate the risks posed by unescaped output and missing security checks.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL querying, the lack of fundamental security checks like nonces and capability checks, coupled with a significant risk of XSS due to poor output escaping, presents a considerable security risk. The external HTTP requests also warrant scrutiny. These weaknesses, despite the absence of known CVEs, suggest that the plugin is not robustly secured against common web application attacks. Further investigation into the specific implementation of file operations and external HTTP requests is recommended, alongside immediate remediation of output escaping and the addition of nonce and capability checks to all relevant entry points.
Key Concerns
- No nonce checks
- No capability checks
- Low output escaping (22%)
- External HTTP requests
- File operations detected
uPlexa WooCommerce Extension Security Vulnerabilities
uPlexa WooCommerce Extension Code Analysis
SQL Query Safety
Output Escaping
uPlexa WooCommerce Extension Attack Surface
Shortcodes 2
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
uPlexa WooCommerce Extension Maintenance & Trust
Maintenance Signals
Community Trust
uPlexa WooCommerce Extension Alternatives
Monero WooCommerce Extension
monero-woocommerce-gateway
Benefits Payment validation done through either monero-wallet-rpc or the xmrchain.net blockchain explorer. Validates payments with cron, so does not …
Autocomplete WooCommerce Orders
autocomplete-woocommerce-orders
Enhance your WooCommerce store with Autocomplete Orders. Automatically complete orders after payment, perfect for virtual goods and subscriptions.
Pledged Plugins PCI Gateway for NMI and WooCommerce
wp-nmi-gateway-pci-woocommerce
PCI Compliant NMI payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
HyperPay Payments
hyperpay-gateways
Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.
Custom Post Type WooCommerce Integration
cpt-woo-integration
Integrates custom post-type with WooCommerce, simplifying management and sales. No need manual product creation for each CPT.
uPlexa WooCommerce Extension Developer Profile
1 plugin · 0 total installs
How We Detect uPlexa WooCommerce Extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/qrcode.min.js/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/clipboard.min.js/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/uplexa-gateway-order-page.js/wp-content/plugins/uplexa-woocommerce-gateway/assets/css/uplexa-gateway-order-page.css/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/qrcode.min.js/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/clipboard.min.js/wp-content/plugins/uplexa-woocommerce-gateway/assets/js/uplexa-gateway-order-page.jsHTML / DOM Fingerprints
uplexa-priceuplexa_gateway_params<span class="uplexa-price"><img src="