BucksBus Security & Risk Analysis

wordpress.org/plugins/bucksbus

Crypto payment gateway for WooCommerce. Accept coins: Bitcoin, Ethereum, Tron, Polygon, USDC, USDT and more.

10 active installs v1.2.5 PHP 7.4+ WP 6.0+ Updated Jan 29, 2026
bitcoincryptocrypto-paymentspayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BucksBus Safe to Use in 2026?

Generally Safe

Score 100/100

BucksBus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "bucksbus" plugin v1.2.5 demonstrates a strong security posture based on the provided static analysis. The absence of identified dangerous functions, use of prepared statements for all SQL queries, and proper output escaping indicate a commitment to secure coding practices. Furthermore, the complete lack of known vulnerabilities, including historical ones, suggests a well-maintained and robust plugin. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation. Capability checks are in place for file operations, adding another layer of defense.

However, the analysis does highlight a few potential areas for improvement. The absence of nonce checks on file operations, despite capability checks being present, could be a minor concern if the file operations themselves are sensitive. Additionally, the plugin makes one external HTTP request, which, while not inherently a vulnerability, represents a potential attack vector if the external service is compromised or the request handling is not robust. The total absence of taint analysis flows is also noteworthy; while it might mean no issues were found, it could also indicate the analysis might have been limited in scope or that the plugin's functionality doesn't lend itself to complex data flows that would trigger taint analysis.

In conclusion, "bucksbus" v1.2.5 appears to be a highly secure plugin with a very small attack surface and no known historical vulnerabilities. The developers have implemented good security practices like prepared statements and output escaping. The main areas for consideration are the lack of nonce checks on file operations and the implications of the single external HTTP request. Overall, the risk is low.

Key Concerns

  • File operations lack nonce checks
  • Plugin makes external HTTP requests
Vulnerabilities
None known

BucksBus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BucksBus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
16 escaped
Nonce Checks
0
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped16 total outputs
Attack Surface

BucksBus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedbucksbus.php:81
filterwoocommerce_payment_gatewaysbucksbus.php:84
actionwoocommerce_blocks_loadedbucksbus.php:87
actionwoocommerce_blocks_payment_method_type_registrationbucksbus.php:185
actionwoocommerce_api_wc_gateway_bucksbusincludes\class-wc-gateway-bucksbus-handler.php:44
actiontemplate_redirectincludes\class-wc-gateway-bucksbus-handler.php:45
Maintenance & Trust

BucksBus Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BucksBus Developer Profile

BucksBus

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BucksBus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bucksbus/assets/js/script.js/wp-content/plugins/bucksbus/assets/css/style.css
Script Paths
/wp-content/plugins/bucksbus/assets/js/script.js
Version Parameters
bucksbus/assets/css/style.css?ver=bucksbus/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bucksbus-gateway-optionbucksbus-provider-option
Data Attributes
data-bucksbus-currencydata-bucksbus-provider
JS Globals
BucksBusBucksBus_API_Handler
FAQ

Frequently Asked Questions about BucksBus