Coinley – Cryptocurrency Payments Security & Risk Analysis

wordpress.org/plugins/coinley-payment-gateway

Accept cryptocurrency payments on your WooCommerce store with lower fees, instant settlements, and no chargebacks.

0 active installs v1.1.5 PHP 7.4+ WP 6.4+ Updated Feb 13, 2026
cryptocurrencyethereumpayment-gatewayusdcwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Coinley – Cryptocurrency Payments Safe to Use in 2026?

Generally Safe

Score 100/100

Coinley – Cryptocurrency Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "coinley-payment-gateway" plugin version 1.1.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce checks and capability checks for all but two AJAX handlers. The absence of known CVEs and a clean vulnerability history is also a strong indicator of robust past development. However, the presence of two AJAX handlers without authentication checks represents a significant concern, creating potential entry points for unauthorized actions if these handlers can be triggered externally. While taint analysis showed no critical or high severity flows, the limited scope of analysis (0 flows) means this data might not be fully representative of all potential data handling issues. The plugin's overall security is generally good due to strong SQL and nonce practices, but the unprotected AJAX endpoints introduce a notable risk that needs to be addressed.

Key Concerns

  • Unprotected AJAX handlers
  • Limited taint analysis scope
Vulnerabilities
None known

Coinley – Cryptocurrency Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Coinley – Cryptocurrency Payments Release Timeline

v1.1.5Current
Code Analysis
Analyzed Mar 17, 2026

Coinley – Cryptocurrency Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
253 escaped
Nonce Checks
20
Capability Checks
19
File Operations
2
External Requests
7
Bundled Libraries
0

Output Escaping

88% escaped288 total outputs
Attack Surface
2 unprotected

Coinley – Cryptocurrency Payments Attack Surface

Entry Points19
Unprotected2

AJAX Handlers 19

authwp_ajax_coinleywp_dismiss_noticecoinleywp.php:142
authwp_ajax_coinleywp_complete_onboardingcoinleywp.php:143
authwp_ajax_coinleywp_create_blocks_ordercoinleywp.php:238
noprivwp_ajax_coinleywp_create_blocks_ordercoinleywp.php:239
authwp_ajax_coinleywp_fetch_transactionsincludes\class-coinleywp-admin.php:44
authwp_ajax_coinleywp_get_transaction_detailsincludes\class-coinleywp-admin.php:45
authwp_ajax_coinleywp_fetch_dashboard_dataincludes\class-coinleywp-admin.php:46
authwp_ajax_coinleywp_update_merchant_settingsincludes\class-coinleywp-admin.php:47
authwp_ajax_coinleywp_test_connectionincludes\class-coinleywp-admin.php:48
authwp_ajax_coinleywp_regenerate_webhook_secretincludes\class-coinleywp-admin.php:49
authwp_ajax_coinleywp_save_network_settingsincludes\class-coinleywp-admin.php:50
authwp_ajax_coinleywp_update_wallet_addressesincludes\class-coinleywp-admin.php:51
authwp_ajax_coinleywp_check_credentialsincludes\class-coinleywp-admin.php:52
authwp_ajax_coinleywp_refresh_credentialsincludes\class-coinleywp-admin.php:53
authwp_ajax_coinleywp_clear_credentialsincludes\class-coinleywp-admin.php:54
authwp_ajax_coinleywp_refresh_walletsincludes\class-coinleywp-admin.php:55
authwp_ajax_coinleywp_fetch_walletsincludes\class-coinleywp-admin.php:56
authwp_ajax_coinleywp_save_walletsincludes\class-coinleywp-admin.php:57
authwp_ajax_coinleywp_test_conversionincludes\class-coinleywp-gateway.php:201
WordPress Hooks 21
actionbefore_woocommerce_initcoinleywp.php:23
actioninitcoinleywp.php:131
actionplugins_loadedcoinleywp.php:132
filterwoocommerce_payment_gatewayscoinleywp.php:133
actionadmin_initcoinleywp.php:140
actionadmin_noticescoinleywp.php:141
actionwoocommerce_blocks_payment_method_type_registrationcoinleywp.php:218
actionwp_enqueue_scriptscoinleywp.php:232
actionadmin_noticescoinleywp.php:242
actioncoinleywp_send_order_emailscoinleywp.php:554
actionadmin_menuincludes\class-coinleywp-admin.php:42
actionadmin_enqueue_scriptsincludes\class-coinleywp-admin.php:43
filterpre_update_option_woocommerce_coinleywp_settingsincludes\class-coinleywp-admin.php:60
actionadmin_noticesincludes\class-coinleywp-admin.php:1571
actionwoocommerce_rest_checkout_process_payment_with_contextincludes\class-coinleywp-blocks-support.php:42
actionwoocommerce_api_coinleywpincludes\class-coinleywp-gateway.php:179
actionwp_enqueue_scriptsincludes\class-coinleywp-gateway.php:180
actionadmin_enqueue_scriptsincludes\class-coinleywp-gateway.php:181
actionadmin_initincludes\class-coinleywp-gateway.php:182
filterwoocommerce_gateway_descriptionincludes\class-coinleywp-gateway.php:185
actionwoocommerce_checkout_update_order_metaincludes\class-coinleywp-gateway.php:188
Maintenance & Trust

Coinley – Cryptocurrency Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version7.4
Downloads190

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Coinley – Cryptocurrency Payments Developer Profile

coinley

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Coinley – Cryptocurrency Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coinley-payment-gateway/assets/css/coinleywp-checkout.css/wp-content/plugins/coinley-payment-gateway/assets/js/coinleywp-checkout.js/wp-content/plugins/coinley-payment-gateway/assets/js/coinleywp-checkout-blocks.js
Script Paths
/wp-content/plugins/coinley-payment-gateway/assets/js/coinleywp-checkout.js/wp-content/plugins/coinley-payment-gateway/assets/js/coinleywp-checkout-blocks.js
Version Parameters
coinley-payment-gateway/assets/css/coinleywp-checkout.css?ver=coinley-payment-gateway/assets/js/coinleywp-checkout.js?ver=coinley-payment-gateway/assets/js/coinleywp-checkout-blocks.js?ver=

HTML / DOM Fingerprints

CSS Classes
coinleywp-checkout-form
HTML Comments
<!-- Removed old AJAX handlers --><!-- CoinleyVanilla SDK now handles all payment processing --><!-- ONLY the blocks order creation handler remains as it's required for WooCommerce Blocks checkout -->
Data Attributes
data-coinleywp-checkout-urldata-coinleywp-order-iddata-coinleywp-payment-request-iddata-coinleywp-payment-status-urldata-coinleywp-site-url
JS Globals
coinleywp_checkout_params
REST Endpoints
/wp-json/coinleywp/v1/create-blocks-order
FAQ

Frequently Asked Questions about Coinley – Cryptocurrency Payments