
Xaman for WooCommerce Security & Risk Analysis
wordpress.org/plugins/xumm-payments-for-woocommerceAccept XRP, EUR, USD, BTC & ETH, using a single plugin with the greatest XRP ledger client (wallet): Xaman (formerly Xumm)!
Is Xaman for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Xaman for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "xumm-payments-for-woocommerce" v1.0.2 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a lack of recorded historical vulnerabilities, significant concerns arise from its attack surface and output handling. The presence of one AJAX handler without authentication checks represents a direct entry point that could be exploited if it handles user-supplied data without proper validation or sanitization, even though taint analysis did not reveal specific exploitable flows in this version. The low percentage of properly escaped output suggests a potential for cross-site scripting (XSS) vulnerabilities, as data displayed to users might not be adequately neutralized, leaving them susceptible to malicious script injection. The reliance on a bundled library like Guzzle could also pose a risk if it's outdated and contains known vulnerabilities, although this is not directly indicated by the provided data. Overall, the plugin has a solid foundation in data handling but requires immediate attention to its authentication mechanisms for AJAX endpoints and output escaping to mitigate potential security risks.
Key Concerns
- AJAX handler without authentication
- Low percentage of properly escaped output
Xaman for WooCommerce Security Vulnerabilities
Xaman for WooCommerce Release Timeline
Xaman for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Xaman for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 20
Maintenance & Trust
Xaman for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Xaman for WooCommerce Alternatives
Bitvolo trustless crypto payment gateway for WooCommerce
bitvolo-trustless-crypto-payment-gateway
This plugin integrates Bitvolo.com trustless cryptocurrency payments (IOTA / Stellar XLM / XRP / EOS / TELOS / WAX) into WooCommerce checkout
XRPTIPBOT Widget by HBENSLAMA
widget-xrptipbot
Displays a XRPTIPBOT tips button to thanks the content creator and boost the vision of the monetized-web based on blockchain technologies.
Ledger Direct
ledger-direct
Accept XRP, EUR, USD directly on the XRP Ledger, using LedgerDirect!
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
Xaman for WooCommerce Developer Profile
1 plugin · 20 total installs
How We Detect Xaman for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xumm-payments-for-woocommerce/admin/css/xumm-for-woocommerce-admin.css/wp-content/plugins/xumm-payments-for-woocommerce/admin/js/xumm-for-woocommerce-admin.jsxumm-for-woocommerce-admin.css?ver=xumm-for-woocommerce-admin.js?ver=