Busha Pay Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/busha-pay

Accept cryptocurrencies through Busha Pay such as Bitcoin, Ethereum, Litecoin and Bitcoin Cash on your WooCommerce store.

0 active installs v1.0.0 PHP 5.6+ WP 3.0+ Updated Unknown
bitcoinbushaecommercewoowoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Busha Pay Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Busha Pay Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the 'busha-pay' v1.0.0 plugin reveals a generally strong security posture, with no critical vulnerabilities identified in the code signals or taint analysis. The plugin demonstrates good practices by consistently using prepared statements for all SQL queries and properly escaping all output, which are fundamental for preventing common web vulnerabilities like SQL injection and cross-site scripting (XSS). The absence of known CVEs and a clean vulnerability history further indicates a history of secure development and maintenance.

However, there are notable areas of concern that significantly detract from its overall security. The plugin lacks any nonce checks and capability checks. This is particularly alarming given the presence of one cron event, which can be triggered externally and potentially without proper authorization or verification. Furthermore, the plugin performs a file operation and an external HTTP request, both of which represent potential attack vectors if not handled with strict validation and sanitization, especially in the absence of any authentication checks on the entry points. While the attack surface appears small in terms of entry points, the lack of security measures on these few points is a critical weakness.

In conclusion, 'busha-pay' v1.0.0 exhibits strengths in its handling of SQL and output, and has a clean historical record. Nevertheless, the complete absence of nonce and capability checks, coupled with file operations and external HTTP requests that lack clear authorization mechanisms, presents a significant risk. The plugin is vulnerable to unauthorized execution of its cron job and potentially to exploitation of its file operations and HTTP requests if they are accessible in an unauthenticated context. These weaknesses need to be addressed to elevate the plugin's security to a more acceptable level.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • File operations without auth checks
  • External HTTP requests without auth checks
  • Cron events without auth checks
Vulnerabilities
None known

Busha Pay Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Busha Pay Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Busha Pay Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitbusha-pay.php:31
filterwoocommerce_valid_order_statuses_for_paymentbusha-pay.php:32
actionbusha_check_ordersbusha-pay.php:33
filterwoocommerce_payment_gatewaysbusha-pay.php:34
filterwc_order_statusesbusha-pay.php:35
actionwoocommerce_admin_order_data_after_order_detailsbusha-pay.php:36
actionwoocommerce_order_details_after_order_tablebusha-pay.php:37
filterwoocommerce_email_order_meta_fieldsbusha-pay.php:38
actionwoocommerce_thankyoubusha-pay.php:39
filtercron_schedulesbusha-pay.php:40
actionplugins_loadedbusha-pay.php:43
filterwoocommerce_order_data_store_cpt_get_orders_queryclass-wc-gateway-busha.php:53
actionwoocommerce_api_wc_gateway_bushaclass-wc-gateway-busha.php:54
actionadmin_enqueue_scriptsclass-wc-gateway-busha.php:55

Scheduled Events 1

busha_check_orders
Maintenance & Trust

Busha Pay Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Busha Pay Payment Gateway for WooCommerce Developer Profile

busha

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Busha Pay Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
busha-pay-data
REST Endpoints
/wc-api/wc_gateway_busha
FAQ

Frequently Asked Questions about Busha Pay Payment Gateway for WooCommerce