
Coinbase Commerce for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/coinbase-commerce-for-contact-form-7Allow user to fill from and pay with Coinbase Commerce, Coinbase Commerce is a Cryptocurrency payment gateway, you can start accepting donation in cry …
Is Coinbase Commerce for Contact Form 7 Safe to Use in 2026?
Mostly Safe
Score 78/100Coinbase Commerce for Contact Form 7 is generally safe to use. 1 past CVE were resolved.
The coinbase-commerce-for-contact-form-7 plugin, version 1.1.2, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, utilizing prepared statements exclusively, which significantly mitigates SQL injection risks. Furthermore, the absence of known vulnerabilities and a clean vulnerability history are strong indicators of a well-maintained and secure codebase in the past. However, the static analysis reveals significant areas of concern. A notable weakness is the presence of two AJAX handlers that lack authentication checks, creating an open attack surface. Additionally, only 38% of outputs are properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The taint analysis, while not revealing critical or high-severity issues, did identify flows with unsanitized paths, which warrants further investigation and could be an indicator of latent risks.
In conclusion, while the plugin benefits from secure database handling and a lack of historical vulnerabilities, the unprotected AJAX endpoints and insufficient output escaping are substantial security weaknesses. These issues, combined with the identified unsanitized paths in taint flows, present clear risks that need to be addressed. The plugin has a moderate to high risk profile due to these exploitable entry points. Developers should prioritize implementing proper authentication for AJAX handlers and ensuring all output is rigorously escaped to improve the plugin's security.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped outputs
- Unsanitized paths in taint flows
- No nonce checks on entry points
- No capability checks on entry points
Coinbase Commerce for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Coinbase Commerce for Contact Form 7 <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter
Coinbase Commerce for Contact Form 7 Release Timeline
Coinbase Commerce for Contact Form 7 Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Coinbase Commerce for Contact Form 7 Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 10
Maintenance & Trust
Coinbase Commerce for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Coinbase Commerce for Contact Form 7 Alternatives
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Crypto Payment Gateway with Instant Payouts
crypto-payment-gateway
Cryptocurrency Payment Gateway with instant payouts to your wallet and without KYC hosted directly on your website.
Coinbase Commerce for Contact Form 7 Developer Profile
9 plugins · 4K total installs
How We Detect Coinbase Commerce for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coinbase-commerce-for-contact-form-7/assets/js/front-end.min.js/wp-content/plugins/coinbase-commerce-for-contact-form-7/assets/js/front-end.min.jscoinbase-commerce-for-contact-form-7/assets/js/front-end.min.js?ver=HTML / DOM Fingerprints
cccf7/wp-json/coinbase-commerce-for-contact-form-7/v1/webhook