Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Security & Risk Analysis

wordpress.org/plugins/bitnob

Accept Bitcoin on your website via on chain or lightning right away. Powered by Bitnob. With an easy setup of our plugin, you can get up and running …

0 active installs v1.1.4 PHP 7.0+ WP 6.0+ Updated Nov 30, 2023
bitcoinbitnoblightningpaymentsshopping-and-more
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Safe to Use in 2026?

Generally Safe

Score 85/100

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "bitnob" v1.1.4 plugin presents a mixed security profile. On the positive side, there are no recorded vulnerabilities in its history, and the static analysis indicates an absence of dangerous functions, SQL injection risks through prepared statements, and a very small attack surface. This suggests a developer who is likely aware of some common security best practices. However, significant concerns emerge from the code analysis. The low percentage of properly escaped output (31%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful examination in conjunction with the unescaped output. Furthermore, the absence of nonce and capability checks on any entry points, although the entry point count is zero, still indicates a lack of protective measures where they might be implicitly needed if functionality were added or changed. The taint analysis, showing unsanitized paths, reinforces the XSS risk, as data processed within these flows could potentially be executed by the browser. While the plugin's history is clean, the current code signals substantial weaknesses that could be exploited.

Key Concerns

  • Low output escaping percentage
  • Taint flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

31% escaped13 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
bitnob_add_gateway (bitnob-payments.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwoocommerce_payment_gatewaysbitnob-payments.php:37
actionplugins_loadedbitnob-payments.php:51
actionwoocommerce_api_wc_gateway_bitnobbitnob-payments.php:127
actionwoocommerce_receipt_bitnobbitnob-payments.php:135
actionwp_headbitnob-payments.php:139
filterwoocommerce_gateway_iconbitnob-payments.php:632
actionbefore_woocommerce_initbitnob-payments.php:664
Maintenance & Trust

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 30, 2023
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bitnob – Accept Bitcoin Payments (On-chain & Lightning) Developer Profile

bitnobmail

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bitnob – Accept Bitcoin Payments (On-chain & Lightning)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bitnob/assets/css/bitnob.css/wp-content/plugins/bitnob/assets/js/inline.js/wp-content/plugins/bitnob/assets/js/bitnob-js.js
Script Paths
/wp-content/plugins/bitnob/assets/js/inline.js/wp-content/plugins/bitnob/assets/js/bitnob-js.js

HTML / DOM Fingerprints

Data Attributes
id="publicKey"id="amount"id="email"id="currency"id="callbackUrl"id="successUrl"+2 more
JS Globals
getFormData
REST Endpoints
/wp-json/bitnob/v1/webhook
FAQ

Frequently Asked Questions about Bitnob – Accept Bitcoin Payments (On-chain & Lightning)