
Bitcoin Online shortcode Security & Risk Analysis
wordpress.org/plugins/bitcoin-onlineDisplay current bitcoin (BTC/USD) price anywhere on your WordPress site online.
Is Bitcoin Online shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Bitcoin Online shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bitcoin-online' v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping are all positive indicators. Furthermore, the plugin has no recorded vulnerability history, which suggests a track record of good security practices. The attack surface is minimal and, critically, all identified entry points appear to be protected by authentication mechanisms, with no unprotected AJAX handlers or REST API routes found.
However, there are a couple of areas for concern. The lack of nonce checks is a significant omission, especially when considering the two shortcodes present. Shortcodes can often be exploited to execute actions on behalf of users, and without nonces, these actions might be vulnerable to Cross-Site Request Forgery (CSRF) attacks. Additionally, the presence of a file operation without further context warrants attention, as file operations can introduce risks if not handled with extreme care and proper validation. While the taint analysis shows no unsanitized flows, the file operation is an entry point that should be monitored closely.
In conclusion, the 'bitcoin-online' plugin demonstrates good fundamental security coding practices and a clean vulnerability history. The primary weakness lies in the absence of nonce checks, which introduces a potential CSRF risk. The file operation, while not flagged by taint analysis, is another point that requires diligence. Overall, the plugin appears relatively secure but has room for improvement regarding CSRF protection.
Key Concerns
- Missing Nonce Checks
- File Operation without explicit details
Bitcoin Online shortcode Security Vulnerabilities
Bitcoin Online shortcode Release Timeline
Bitcoin Online shortcode Code Analysis
SQL Query Safety
Output Escaping
Bitcoin Online shortcode Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Bitcoin Online shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Bitcoin Online shortcode Alternatives
Octillion Widget for BTC-e PAMM
octillion-widget-for-btc-e-pamm-account
Widget shows daily statistics of BTC-E PAMM account
MugglePay
mugglepay
MugglePay is a WooCommerce payment gateway for accepting cryptocurrency payments (e.g. USDC, USDT, Ethereum, Solana) with real-time settlement.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce
mycryptocheckout
Cryptocurrency payment gateway for WooCommerce and Easy Digital Downloads. Accept 100+ coins: Bitcoin, Ethereum, BNB, Solana. Peer2Peer transactions.
Bitcoin Payments – Blockonomics
blockonomics-bitcoin-payments
Accept Bitcoin/USDT payments on your WooCommerce website. Crypto payments go directly to your wallet.
Bitcoin Online shortcode Developer Profile
1 plugin · 10 total installs
How We Detect Bitcoin Online shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bitcoin-online/assets/css/admin.css/wp-content/plugins/bitcoin-online/assets/js/admin.js/wp-content/plugins/bitcoin-online/assets/js/jquery.number.min.jshttp://cdn.pubnub.com/pubnub.min.jsbitcoin-online/assets/js/admin.js?ver=bitcoin-online/assets/css/admin.css?ver=HTML / DOM Fingerprints
bitcoin-online-shortcode<!-- Bitcoin Online Shortcode Start --><!-- Bitcoin Online Shortcode End -->pubnub[bitcoin_online]