
Coin Miner – Coin Hive, and CoinImp monero miner Security & Risk Analysis
wordpress.org/plugins/coin-minerThis plugin helps you to earn money from visitors on your site by Mining monero.
Is Coin Miner – Coin Hive, and CoinImp monero miner Safe to Use in 2026?
Generally Safe
Score 85/100Coin Miner – Coin Hive, and CoinImp monero miner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "coin-miner" v1.0.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by having no known vulnerabilities (CVEs) and a relatively small attack surface with all identified entry points (AJAX handlers) reportedly secured by authentication checks. The absence of taint analysis findings and critical code signals is also encouraging. However, there are significant concerns lurking within the static analysis results. The plugin executes a substantial number of SQL queries (10 total) with 0% utilizing prepared statements, creating a high risk of SQL injection vulnerabilities. Furthermore, while most output is properly escaped, there's still a percentage that is not, which could lead to cross-site scripting (XSS) issues if the unescaped output is user-controllable.
Despite the lack of historical vulnerabilities, the current code base exhibits weaknesses that could be exploited. The SQL query handling is a critical flaw that overshadows the otherwise clean code signals. The vulnerability history shows a clean slate, which is a positive indicator, but it doesn't negate the risks inherent in the current implementation. The plugin's strengths lie in its protected entry points and lack of critical code signals and CVEs. The primary weakness is the lack of prepared statements for all SQL queries.
Key Concerns
- All SQL queries use raw SQL statements
- Some outputs are not properly escaped
Coin Miner – Coin Hive, and CoinImp monero miner Security Vulnerabilities
Coin Miner – Coin Hive, and CoinImp monero miner Code Analysis
SQL Query Safety
Output Escaping
Coin Miner – Coin Hive, and CoinImp monero miner Attack Surface
AJAX Handlers 4
WordPress Hooks 12
Maintenance & Trust
Coin Miner – Coin Hive, and CoinImp monero miner Maintenance & Trust
Maintenance Signals
Community Trust
Coin Miner – Coin Hive, and CoinImp monero miner Alternatives
Cryptocurrency Mining Pools
cryptocurrency-mining-pools
Displays a list of mining pools in your WordPress sidebar or any widget area.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Coin Miner – Coin Hive, and CoinImp monero miner Developer Profile
1 plugin · 10 total installs
How We Detect Coin Miner – Coin Hive, and CoinImp monero miner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coin-miner/css/style.css/wp-content/plugins/coin-miner/js/js.js/wp-content/plugins/coin-miner/js/js.jsHTML / DOM Fingerprints
cm_admin_ajaxcm_miner_ajax