Buy Widget Coinbase Security & Risk Analysis

wordpress.org/plugins/buy-widget-coinbase

Coinbase "Buy Widget" for WordPress

10 active installs v1.1 PHP 7.2+ WP 4.9+ Updated Nov 2, 2018
bitcoinbitcoincashcoinbaseethereumlitecoin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buy Widget Coinbase Safe to Use in 2026?

Generally Safe

Score 85/100

Buy Widget Coinbase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "buy-widget-coinbase" v1.1 plugin exhibits a strong security posture based on the provided static analysis data. The absence of any identified dangerous functions, SQL queries without prepared statements, or file operations is highly commendable. Furthermore, the excellent output escaping rate (82%) significantly mitigates the risk of cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is also a positive indicator of its development and maintenance practices.

However, a notable area of concern is the complete lack of nonce checks and capability checks. While the plugin currently presents a minimal attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes, this absence of authentication and authorization checks means that if such entry points were introduced in future versions or through interaction with other plugins, they would be inherently unprotected. The taint analysis showing zero flows with unsanitized paths is positive, but this is within a context of zero analyzed flows, which might be due to a very small or non-existent code path interacting with external inputs.

In conclusion, the current version of "buy-widget-coinbase" appears secure due to its minimal feature set and good coding practices. The primary weakness lies in the lack of fundamental security checks (nonces and capabilities) which, while not immediately exploitable given the current attack surface, represent a latent risk for future development or integration. The absence of vulnerability history is positive but should be viewed alongside the limited scope of the current plugin.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Taint analysis: 0 flows analyzed
Vulnerabilities
None known

Buy Widget Coinbase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Buy Widget Coinbase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped57 total outputs
Attack Surface

Buy Widget Coinbase Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initbuy-widget-coinbase.php:23
actionadmin_menubuy-widget-coinbase.php:24
actionwidgets_initbuy-widget-coinbase.php:201
Maintenance & Trust

Buy Widget Coinbase Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 2, 2018
PHP min version7.2
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Buy Widget Coinbase Developer Profile

nurikabe

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buy Widget Coinbase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buy-widget-coinbase/style.css

HTML / DOM Fingerprints

CSS Classes
coinbase-widgetcoinbase-widget-async-loaderwp_widget_plugin_box
Data Attributes
data-addressdata-amountdata-codedata-currencydata-crypto_currency
Shortcode Output
<a class="coinbase-widget"id="coinbase_widget"data-address=data-amount=
FAQ

Frequently Asked Questions about Buy Widget Coinbase