Bitfinex Pay Security & Risk Analysis

wordpress.org/plugins/bitfinex-pay

Allows e-commerce customers to pay for goods and services with crypto currencies. It provides a payment gateway that could be used by any e-commerce t …

10 active installs v3.2.1 PHP 7.4+ WP 6.0+ Updated Nov 1, 2024
bitcoinbitcoin-paymentsbitfinex-paycrypto-paymentstether-token
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bitfinex Pay Safe to Use in 2026?

Generally Safe

Score 92/100

Bitfinex Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'bitfinex-pay' plugin version 3.2.1 presents a mixed security posture. On the positive side, the plugin reports no known historical vulnerabilities (CVEs) and shows no critical or high severity taint flows. It also correctly utilizes prepared statements for all SQL queries, indicating good database interaction practices. The absence of external HTTP requests and a small attack surface further contribute to its security.

However, several concerns warrant attention. The most significant is the very low percentage (22%) of properly escaped output, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. File operations are present but not detailed, which could be a potential vector if not handled securely. The lack of any capability checks or nonce checks on its entry points, even though the attack surface is currently reported as zero, leaves it vulnerable if new entry points are added in the future without proper authorization. The bundled Guzzle library also requires scrutiny for potential outdated versions.

Overall, while the absence of known vulnerabilities and secure SQL practices are strengths, the significant output escaping issues and potential for unauthenticated access to future entry points represent considerable risks. The plugin's security would be significantly improved by addressing the output escaping and implementing robust authorization checks.

Key Concerns

  • Low output escaping percentage
  • No capability checks
  • No nonce checks
  • Bundled library (Guzzle) potential risk
Vulnerabilities
None known

Bitfinex Pay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bitfinex Pay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

22% escaped18 total outputs
Attack Surface

Bitfinex Pay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedbfx-pay-woocommerce.php:23
actionwoocommerce_after_add_to_cart_formbfx-pay-woocommerce.php:24
actiontemplate_redirectbfx-pay-woocommerce.php:25
filterwoocommerce_payment_gatewaysbfx-pay-woocommerce.php:28
filterplugin_row_metabfx-pay-woocommerce.php:29
actionbefore_woocommerce_initbfx-pay-woocommerce.php:32
actionwoocommerce_blocks_loadedbfx-pay-woocommerce.php:33
filtercron_schedulesbfx-pay-woocommerce.php:37
actionbfx_pay_cron_hookbfx-pay-woocommerce.php:38
actionwpbfx-pay-woocommerce.php:39
actionwoocommerce_blocks_payment_method_type_registrationbfx-pay-woocommerce.php:59
actionwoocommerce_email_order_detailsincludes\class-wc-bfx-pay-gateway.php:78
actionwoocommerce_email_order_detailsincludes\class-wc-bfx-pay-gateway.php:79
actionwoocommerce_api_bitfinexincludes\class-wc-bfx-pay-gateway.php:80
filterwoocommerce_add_errorincludes\class-wc-bfx-pay-gateway.php:82

Scheduled Events 1

bfx_pay_cron_hook
Maintenance & Trust

Bitfinex Pay Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 1, 2024
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Bitfinex Pay Developer Profile

Bitfinex

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bitfinex Pay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bitfinex-pay/includes/checkout.css
Version Parameters
bitfinex-pay/includes/checkout.css?ver=plugin_version

HTML / DOM Fingerprints

CSS Classes
loop-checkout-btn
Data Attributes
data-button-typedata-site-iddata-urldata-iddata-order-iddata-amount+6 more
JS Globals
window.BfxPaywindow.bfx_pay_data
FAQ

Frequently Asked Questions about Bitfinex Pay