Coinbase Business for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/coinbase-commerce-for-contact-form-7

Accept cryptocurrency payments on Contact Form 7 using Coinbase Business Checkouts API (USDC on Base by default).

10 active installs v1.2.0 PHP 7.4+ WP 4.9+ Updated May 18, 2026
coinbase-businesscontact-form-7cryptodonationgateway
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 11, 2026
Safety Verdict

Is Coinbase Business for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 99/100

Coinbase Business for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 11, 2026Updated 3mo ago
Risk Assessment

The coinbase-commerce-for-contact-form-7 plugin, version 1.1.2, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, utilizing prepared statements exclusively, which significantly mitigates SQL injection risks. Furthermore, the absence of known vulnerabilities and a clean vulnerability history are strong indicators of a well-maintained and secure codebase in the past. However, the static analysis reveals significant areas of concern. A notable weakness is the presence of two AJAX handlers that lack authentication checks, creating an open attack surface. Additionally, only 38% of outputs are properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The taint analysis, while not revealing critical or high-severity issues, did identify flows with unsanitized paths, which warrants further investigation and could be an indicator of latent risks.

In conclusion, while the plugin benefits from secure database handling and a lack of historical vulnerabilities, the unprotected AJAX endpoints and insufficient output escaping are substantial security weaknesses. These issues, combined with the identified unsanitized paths in taint flows, present clear risks that need to be addressed. The plugin has a moderate to high risk profile due to these exploitable entry points. Developers should prioritize implementing proper authentication for AJAX handlers and ensuring all output is rigorously escaped to improve the plugin's security.

Key Concerns

  • AJAX handlers without authentication checks
  • Low percentage of properly escaped outputs
  • Unsanitized paths in taint flows
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1 published

Coinbase Business for Contact Form 7 Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-6709medium · 4.3Missing Authorization

Coinbase Commerce for Contact Form 7 <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter

May 11, 2026 Patched in 1.2.0 (58d)
Version History

Coinbase Business for Contact Form 7 Release Timeline

v1.2.0Current
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Coinbase Business for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
10
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

38% escaped16 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_settings (includes/class-admin-settings.php:227)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Coinbase Business for Contact Form 7 Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_cccf7-form-submitincludes/class-user.php:50
noprivwp_ajax_cccf7-form-submitincludes/class-user.php:51

REST API Routes 1

POST/wp-json/cccf7/v1/complete-paymentincludes/class-webhook.php:48
WordPress Hooks 10
actionwpcf7_after_saveincludes/class-admin-settings.php:49
actionadmin_menuincludes/class-admin-settings.php:50
actionadmin_post_cccf7_save_settingsincludes/class-admin-settings.php:51
actioninitincludes/class-admin-settings.php:52
actionmanage_cccf7-payments_posts_columnsincludes/class-admin-settings.php:53
actionmanage_cccf7-payments_posts_custom_columnincludes/class-admin-settings.php:54
filterwpcf7_editor_panelsincludes/class-admin-settings.php:65
actionadmin_noticesincludes/class-cccf7-init.php:58
actionwp_enqueue_scriptsincludes/class-user.php:49
actionrest_api_initincludes/class-webhook.php:37
Maintenance & Trust

Coinbase Business for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 18, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Coinbase Business for Contact Form 7 Developer Profile

CoderPress

10 plugins · 5K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Coinbase Business for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coinbase-commerce-for-contact-form-7/assets/js/front-end.min.js
Script Paths
/wp-content/plugins/coinbase-commerce-for-contact-form-7/assets/js/front-end.min.js
Version Parameters
coinbase-commerce-for-contact-form-7/assets/js/front-end.min.js?ver=

HTML / DOM Fingerprints

JS Globals
cccf7
REST Endpoints
/wp-json/coinbase-commerce-for-contact-form-7/v1/webhook
FAQ

Frequently Asked Questions about Coinbase Business for Contact Form 7