
SendBSV BSV Payments for WooCommerce Security & Risk Analysis
wordpress.org/plugins/bsvanon-bitcoin-sv-paymentsAccept Bitcoin SV payments directly to your wallet. Self-custody, no third-party processor. Modern fork with PHP 8+ and WooCommerce HPOS support.
Is SendBSV BSV Payments for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100SendBSV BSV Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bsvanon-bitcoin-sv-payments" plugin v6.2.0 exhibits a generally strong security posture with several good practices in place. All identified entry points (AJAX handlers) have authentication checks, and all SQL queries utilize prepared statements, indicating a conscious effort to prevent common vulnerabilities like SQL injection. The plugin also demonstrates a high level of output escaping, which is crucial for mitigating Cross-Site Scripting (XSS) risks. However, the presence of two `unserialize` calls is a significant concern, as this function can lead to Remote Code Execution (RCE) if not handled with extreme caution and proper input validation, especially with potentially untrusted data. The taint analysis reveals 5 high-severity flows with unsanitized paths, which, when combined with the dangerous `unserialize` functions, strongly suggests a high risk of severe vulnerabilities, likely RCE or privilege escalation, if the tainted data reaches the `unserialize` function without proper sanitization.
The plugin's vulnerability history shows no recorded CVEs, which is a positive sign that suggests a lack of publicly disclosed vulnerabilities in the past. This might indicate a dedicated development team or a fortunate history. However, the absence of past vulnerabilities does not negate the risks identified in the static and taint analyses. The current code signals, particularly the `unserialize` functions and high-severity tainted flows, present a substantial and immediate risk that needs to be addressed. While the plugin has strengths in areas like prepared statements and output escaping, the identified `unserialize` calls coupled with unsanitized tainted data create a critical security weakness that outweighs these positive aspects.
Key Concerns
- High severity unsanitized taint flows
- Use of dangerous unserialize function
- File operations detected
- External HTTP requests detected
SendBSV BSV Payments for WooCommerce Security Vulnerabilities
SendBSV BSV Payments for WooCommerce Release Timeline
SendBSV BSV Payments for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SendBSV BSV Payments for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 25
Scheduled Events 2
Maintenance & Trust
SendBSV BSV Payments for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SendBSV BSV Payments for WooCommerce Alternatives
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Helio Pay (Accept 1-click crypto payments #USDC #SOL #BTC #ETH)
helio
Helio Pay ⚡⚡ Sell more with crypto ⚡⚡ - Accept crypto payments the easy way - Set up in minutes & get paid instantly with real-time payouts - Sell …
Accept Bitcoin instantly via OpenNode
opennode-for-woocommerce
Start accepting Bitcoin instantly through Lightning Network today. Powered by OpenNode
ShieldClimb – Crypto Payment Gateway for WooCommerce
shieldclimb-crypto-payment-gateway
Crypto Payment Gateway with instant payouts—accept cryptocurrency with no registration, no KYC, and no delays. Your crypto, your control.
LapinoPay – Instant USDC Payment Gateway
lapinopay
Accept instant USD/EUR payments with USDC conversion. Support for credit cards, Apple Pay, Google Pay, and Revolut with instant payouts.
SendBSV BSV Payments for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect SendBSV BSV Payments for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-admin-gateway.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-checkout-gateway.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-modal.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-qr.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/css/bw-bsw-admin-gateway.css/wp-content/plugins/bsvanon-bitcoin-sv-payments/css/bw-bsw-checkout-gateway.css/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-admin-gateway.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-checkout-gateway.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-modal.js/wp-content/plugins/bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-qr.jsbsvanon-bitcoin-sv-payments/js/bw-bsw-admin-gateway.js?ver=bsvanon-bitcoin-sv-payments/js/bw-bsw-checkout-gateway.js?ver=bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-modal.js?ver=bsvanon-bitcoin-sv-payments/js/bw-bsw-payment-gateway-qr.js?ver=bsvanon-bitcoin-sv-payments/css/bw-bsw-admin-gateway.css?ver=bsvanon-bitcoin-sv-payments/css/bw-bsw-checkout-gateway.css?ver=HTML / DOM Fingerprints
bw-bsw-payment-modal<!-- v6.0.0: Removed top-up link from checkout (A0.3 - merchant trust + WP.org concerns) --><!-- Top-up link now only appears on payment console page after checkout --><!-- v6.0.0: Blocks support is now complete via class-bsv-blocks-integration.php --><!-- No warning needed - both classic and Blocks checkout work seamlessly -->data-bsv-payment-modal-targetwindow.BWWC_Gateway