Xaman for WooCommerce Security & Risk Analysis

wordpress.org/plugins/xumm-payments-for-woocommerce

Accept XRP, EUR, USD, BTC & ETH, using a single plugin with the greatest XRP ledger client (wallet): Xaman (formerly Xumm)!

20 active installs v1.0.2 PHP 8.2+ WP 4.7+ Updated Unknown
cryptoledgerxamanxrpxumm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xaman for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Xaman for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "xumm-payments-for-woocommerce" v1.0.2 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a lack of recorded historical vulnerabilities, significant concerns arise from its attack surface and output handling. The presence of one AJAX handler without authentication checks represents a direct entry point that could be exploited if it handles user-supplied data without proper validation or sanitization, even though taint analysis did not reveal specific exploitable flows in this version. The low percentage of properly escaped output suggests a potential for cross-site scripting (XSS) vulnerabilities, as data displayed to users might not be adequately neutralized, leaving them susceptible to malicious script injection. The reliance on a bundled library like Guzzle could also pose a risk if it's outdated and contains known vulnerabilities, although this is not directly indicated by the provided data. Overall, the plugin has a solid foundation in data handling but requires immediate attention to its authentication mechanisms for AJAX endpoints and output escaping to mitigate potential security risks.

Key Concerns

  • AJAX handler without authentication
  • Low percentage of properly escaped output
Vulnerabilities
None known

Xaman for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Xaman for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
4 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

22% escaped18 total outputs
Attack Surface
1 unprotected

Xaman for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_create_payloadincludes\class-xumm-for-woocommerce.php:187
WordPress Hooks 20
filteradmin_initadmin\class-xumm-for-woocommerce-admin.php:419
actionplugins_loadedincludes\class-xumm-for-woocommerce.php:155
actionplugins_loadedincludes\class-xumm-for-woocommerce.php:171
actionadmin_noticesincludes\class-xumm-for-woocommerce.php:173
actionadmin_bar_menuincludes\class-xumm-for-woocommerce.php:174
actionadmin_menuincludes\class-xumm-for-woocommerce.php:176
filterplugin_action_links_xumm-payments-for-woocommerce/xumm-payments-for-woocommerce.phpincludes\class-xumm-for-woocommerce.php:178
actionadmin_enqueue_scriptsincludes\class-xumm-for-woocommerce.php:180
actionadmin_enqueue_scriptsincludes\class-xumm-for-woocommerce.php:181
filterxumm_init_form_fieldsincludes\class-xumm-for-woocommerce.php:183
filterxumm_display_plugin_optionsincludes\class-xumm-for-woocommerce.php:185
actionwp_enqueue_scriptsincludes\class-xumm-for-woocommerce.php:201
actionwp_enqueue_scriptsincludes\class-xumm-for-woocommerce.php:202
filterwoocommerce_payment_gatewaysincludes\class-xumm-for-woocommerce.php:206
filterwoocommerce_available_payment_gatewaysincludes\class-xumm-for-woocommerce.php:207
filterwoocommerce_currenciesincludes\class-xumm-for-woocommerce.php:208
filterwoocommerce_currency_symbolincludes\class-xumm-for-woocommerce.php:209
actionwoocommerce_update_options_payment_gateways_xummsrc\Woocommerce\XummPaymentGateway.php:108
actionwoocommerce_api_xummsrc\Woocommerce\XummPaymentGateway.php:110
actionwoocommerce_xumm_deactivatesrc\Woocommerce\XummPaymentGateway.php:111
Maintenance & Trust

Xaman for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedUnknown
PHP min version8.2
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Xaman for WooCommerce Developer Profile

xumm

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Xaman for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xumm-payments-for-woocommerce/admin/css/xumm-for-woocommerce-admin.css/wp-content/plugins/xumm-payments-for-woocommerce/admin/js/xumm-for-woocommerce-admin.js
Version Parameters
xumm-for-woocommerce-admin.css?ver=xumm-for-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Xaman for WooCommerce