ALFAcoins for WooCommerce Security & Risk Analysis

wordpress.org/plugins/alfacoins-for-woocommerce

Accept all major cryptocurrencies like Bitcoin, Ethereum, TRC-20 & ERC-20 Tether, TRX, Litecoin, XRP with ALFAcoins plugin for WooCommerce.

10 active installs v1.0 PHP 7.4+ WP 4.3.1+ Updated Feb 29, 2024
bitcoincryptodogecoinethereumlitecoin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ALFAcoins for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

ALFAcoins for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "alfacoins-for-woocommerce" plugin version 1.0 exhibits several concerning security practices that create a notable risk. While the static analysis reports no dangerous functions, file operations, or critical taint flows, the absence of critical security checks is alarming. The presence of an unprotected AJAX handler is a significant vulnerability, as it represents an easily exploitable entry point for attackers. Furthermore, the complete lack of nonce and capability checks on any entry points, including the AJAX handler, leaves the plugin open to various attacks such as Cross-Site Request Forgery (CSRF) and privilege escalation. The 100% of SQL queries not using prepared statements is also a critical flaw, paving the way for SQL injection vulnerabilities. The plugin's vulnerability history is currently clear, which is a positive sign, but it does not negate the immediate risks identified in the code analysis. The lack of identified vulnerabilities in the past could be due to low usage, limited security auditing, or simply that these weaknesses haven't been exploited or discovered yet. In conclusion, while the plugin has no known past vulnerabilities, its current implementation demonstrates a significant lack of fundamental security controls, making it a high-risk component for any WordPress site. The unprotected AJAX handler and the absence of prepared statements for all SQL queries are immediate and severe threats.

Key Concerns

  • AJAX handler without auth checks
  • SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
  • Unescaped output on 29% of outputs
Vulnerabilities
None known

ALFAcoins for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ALFAcoins for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

71% escaped14 total outputs
Attack Surface
1 unprotected

ALFAcoins for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_alfacoins_create_invoiceclass-wc-gateway-alfacoins.php:949
WordPress Hooks 6
actionplugins_loadedclass-wc-gateway-alfacoins.php:19
actionwoocommerce_api_wc_gateway_alfacoinsclass-wc-gateway-alfacoins.php:115
filterwoocommerce_payment_gatewaysclass-wc-gateway-alfacoins.php:924
filterplugin_action_linksclass-wc-gateway-alfacoins.php:929
actionwoocommerce_blocks_loadedclass-wc-gateway-alfacoins.php:951
actionwoocommerce_blocks_payment_method_type_registrationclass-wc-gateway-alfacoins.php:957
Maintenance & Trust

ALFAcoins for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedFeb 29, 2024
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

ALFAcoins for WooCommerce Developer Profile

ALFAcoins

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ALFAcoins for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alfacoins-for-woocommerce/assets/img/icon.png

HTML / DOM Fingerprints

Data Attributes
data-alfacoins-redirectdata-alfacoins-modal
JS Globals
alfacoins_params
REST Endpoints
/wp-json/alfacoins/v1/callback
FAQ

Frequently Asked Questions about ALFAcoins for WooCommerce