XPayr Crypto Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/xpayr-crypto-gateway-for-woocommerce

Accept crypto payments in WooCommerce with XPayr's non-custodial hosted checkout, flat 0.5% fees, and real-time payment sync.

0 active installs v0.2.5 PHP 7.4+ WP 6.0+ Updated Mar 16, 2026
bitcoin-paymentscrypto-payment-gatewaycryptocurrencyusdt-paymentsweb3-checkout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is XPayr Crypto Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

XPayr Crypto Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The xpayr-crypto-gateway-for-woocommerce plugin, in version 0.2.5, presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, output escaping, and avoids the use of dangerous functions or file operations. It also has a clean vulnerability history with no recorded CVEs, suggesting a generally stable codebase. However, a significant concern arises from the static analysis which reveals one unprotected REST API route. This is a critical entry point that could potentially be exploited if it handles user-supplied data without proper authorization checks, exposing the site to various attacks. The absence of nonce checks further exacerbates this risk, as it bypasses a common WordPress security mechanism for verifying the integrity of requests. While taint analysis shows no immediate critical or high severity flows, the identified unprotected REST API route is a weakness that needs immediate attention. The plugin's strengths in other areas are overshadowed by this single but significant oversight in its entry point handling.

Key Concerns

  • Unprotected REST API route
  • Missing nonce checks
Vulnerabilities
None known

XPayr Crypto Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

XPayr Crypto Gateway for WooCommerce Release Timeline

v0.2.5Current
v0.2.4
Code Analysis
Analyzed Apr 16, 2026

XPayr Crypto Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface
1 unprotected

XPayr Crypto Gateway for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/xpayr/v1/webhookxpayr-crypto-gateway-for-woocommerce.php:152
WordPress Hooks 7
actionbefore_woocommerce_initxpayr-crypto-gateway-for-woocommerce.php:41
actionbefore_woocommerce_initxpayr-crypto-gateway-for-woocommerce.php:61
actionwoocommerce_blocks_loadedxpayr-crypto-gateway-for-woocommerce.php:77
actionwoocommerce_blocks_payment_method_type_registrationxpayr-crypto-gateway-for-woocommerce.php:84
actionplugins_loadedxpayr-crypto-gateway-for-woocommerce.php:110
actionrest_api_initxpayr-crypto-gateway-for-woocommerce.php:147
filterwoocommerce_payment_gatewaysxpayr-crypto-gateway-for-woocommerce.php:806
Maintenance & Trust

XPayr Crypto Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 16, 2026
PHP min version7.4
Downloads285

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

XPayr Crypto Gateway for WooCommerce Developer Profile

XPayr

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XPayr Crypto Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xpayr-crypto-gateway-for-woocommerce/assets/images/xpayr.png

HTML / DOM Fingerprints

Data Attributes
data-gateway-id="xpayrcgfw_gateway"data-url="/wp-json/xpayr/v1/webhook"data-nonce="
JS Globals
window.XPayrCryptoGateway
REST Endpoints
/wp-json/xpayr/v1/webhook
FAQ

Frequently Asked Questions about XPayr Crypto Gateway for WooCommerce