
BoomFi Crypto Payments for WooCommerce Security & Risk Analysis
wordpress.org/plugins/boomfi-crypto-paymentsThe BoomFi Crypto Payments Plugin enables e-commerce stores to effortlessly accept cryptocurrency payments through WooCommerce.
Is BoomFi Crypto Payments for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100BoomFi Crypto Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "boomfi-crypto-payments" v1.18.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices by having no critical or high-severity vulnerabilities in its history, and no known unpatched CVEs. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface, which is a significant strength. Furthermore, the code signals indicate the absence of dangerous functions and file operations, and all SQL queries are properly prepared. The plugin also shows a good rate of output escaping (79%) and includes at least one nonce check.
However, there are a few areas for concern. The taint analysis, while showing no critical or high severity issues, did identify two flows with unsanitized paths. This, along with the presence of external HTTP requests and a lack of capability checks, suggests potential avenues for exploitation if these areas are not carefully managed. The fact that 21% of outputs are not properly escaped could lead to cross-site scripting (XSS) vulnerabilities in certain scenarios.
Overall, the plugin's lack of historical vulnerabilities and its robust handling of SQL and core entry points are commendable. Nevertheless, the identified unsanitized paths and unescaped outputs, coupled with the absence of capability checks and the use of external HTTP requests, warrant attention. While the current risk appears low, these areas present opportunities for future improvement to further strengthen the plugin's security.
Key Concerns
- Flows with unsanitized paths found
- Unescaped output (21%)
- External HTTP requests present
- No capability checks
BoomFi Crypto Payments for WooCommerce Security Vulnerabilities
BoomFi Crypto Payments for WooCommerce Release Timeline
BoomFi Crypto Payments for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
BoomFi Crypto Payments for WooCommerce Attack Surface
WordPress Hooks 16
Maintenance & Trust
BoomFi Crypto Payments for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
BoomFi Crypto Payments for WooCommerce Alternatives
AllScale Checkout
allscale-checkout
Accept crypto payments with 0.6% fees (min $0.10) and instant USDT settlement to your own wallet. Non-custodial. Requires WooCommerce.
Meum Crypto Payments for WooCommerce
meum-crypto-payments-for-woocommerce
Accept crypto payments in WooCommerce. Receive settlement in supported USD stablecoins directly to your configured wallet.
MutoPay for WooCommerce
mutopay-for-woocommerce
Accept crypto payments in your WooCommerce store via MutoPay. Customers pay with any token on 7+ chains, you receive stablecoins.
RizzPay for WooCommerce: High-Risk & Crypto Payment Gateway
rizzpay-for-woocommerce
Crypto and high-risk payment gateway for WooCommerce. Accept 180+ methods and settle in USDC to a wallet you control.
Stablezact Crypto Payments for WooCommerce
stablezact-crypto-payments
Accept cryptocurrency payments on your WooCommerce store with lower fees, instant settlements, and no chargebacks.
BoomFi Crypto Payments for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect BoomFi Crypto Payments for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boomfi-crypto-payments/assets/css/boomfi-crypto-payments-checkout.css/wp-content/plugins/boomfi-crypto-payments/assets/js/boomfi-crypto-payments-checkout.js/wp-content/plugins/boomfi-crypto-payments/assets/js/boomfi-crypto-payments-admin.jsboomfi-crypto-payments/assets/css/boomfi-crypto-payments-checkout.css?ver=boomfi-crypto-payments/assets/js/boomfi-crypto-payments-checkout.js?ver=boomfi-crypto-payments/assets/js/boomfi-crypto-payments-admin.js?ver=HTML / DOM Fingerprints
boomfi-crypto-payments-checkout-notice<!-- BoomFi Crypto Payments: Meta box --><!-- End BoomFi Crypto Payments: Meta box -->data-gateway-id="boomfi-crypto-payments"boomfi_crypto_payments_params/wp-json/boomfi-crypto-payments/v1/payment-status/wp-json/boomfi-crypto-payments/v1/payment-processed