
Check Wallet Security & Risk Analysis
wordpress.org/plugins/check-walletCheck the balance of your Bitcoin wallet
Is Check Wallet Safe to Use in 2026?
Generally Safe
Score 85/100Check Wallet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "check-wallet" plugin v1.5 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, exclusively utilizing prepared statements, and has no recorded vulnerabilities or CVEs. The static analysis also shows a very small attack surface, with only one entry point identified (a shortcode) and no AJAX handlers or REST API routes contributing to it. Furthermore, there are no file operations or external HTTP requests, which generally reduces potential risks.
However, significant concerns arise from the output escaping and taint analysis. A striking 0% of the 8 identified outputs are properly escaped, meaning that any data rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks. This is further compounded by a taint flow analysis that reveals one instance of an unsanitized path. While the severity is not classified as critical or high, the presence of unsanitized paths and unescaped output presents a clear risk of code injection or data leakage.
In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the unescaped output and unsanitized path represent critical weaknesses. The lack of explicit capability checks or nonce checks on its single entry point, combined with the unescaped output, suggests a potential for privilege escalation or XSS if user-supplied data is involved in the shortcode's functionality. These areas require immediate attention to improve the plugin's overall security.
Key Concerns
- Unescaped output detected (8 outputs, 0% escaped)
- Flow with unsanitized paths detected
- No capability checks on entry points
- No nonce checks on entry points
Check Wallet Security Vulnerabilities
Check Wallet Code Analysis
Output Escaping
Data Flow Analysis
Check Wallet Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Check Wallet Maintenance & Trust
Maintenance Signals
Community Trust
Check Wallet Alternatives
Disable Author Pages
disable-author-pages
Disable the author pages
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Crypto Converter ⚡ Widget
crypto-converter-widget
Effortless ❤️ crypto/fiat conversion: ⚡ live, secure, fast, customizable WP 📟 widget—no API keys needed, completely free!
Sidebar Shortcode
thinker-sidebar-shortcode
Add sidebars to WordPress posts and pages using shortcodes with a sidebar Name or ID.
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
Check Wallet Developer Profile
10 plugins · 220 total installs
How We Detect Check Wallet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/check-wallet/go.phpHTML / DOM Fingerprints
check-wallet<div class="check-wallet"><center><form action="method="get" target="_blank"><input type="text" name="address" placeholder="">