
CoinMall Security & Risk Analysis
wordpress.org/plugins/coinmallAccept cryptocurrency on your WooCommerce stores through CoinMall.com
Is CoinMall Safe to Use in 2026?
Generally Safe
Score 85/100CoinMall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "coinmall" v1.0.0 plugin presents a mixed security picture. On the positive side, there are no recorded vulnerabilities (CVEs) and the plugin utilizes prepared statements for all SQL queries, indicating good database security practices. The static analysis also shows no detected taint flows, dangerous functions, or indications of bundled outdated libraries. However, significant concerns arise from the lack of output escaping for all identified output points. This means that data displayed to users or other systems could potentially be manipulated, leading to cross-site scripting (XSS) vulnerabilities if user-controlled input is involved in these outputs. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points is a critical oversight, leaving the plugin susceptible to various forms of unauthorized actions and privilege escalation. While the attack surface appears small in terms of AJAX handlers, REST API routes, and shortcodes, the lack of basic security checks on the single cron event and the general absence of capability checks leave the plugin vulnerable. The plugin's vulnerability history is clean, but this does not negate the inherent risks identified in the current code analysis. The strengths lie in SQL handling and the absence of known vulnerabilities, but the weaknesses in output escaping and authorization checks are significant risks that need immediate attention.
Key Concerns
- No output escaping found
- No capability checks found
- No nonce checks found
CoinMall Security Vulnerabilities
CoinMall Code Analysis
Output Escaping
CoinMall Attack Surface
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
CoinMall Maintenance & Trust
Maintenance Signals
Community Trust
CoinMall Alternatives
Whitepay Payment Gateway for WooCommerce
whitepay-for-woocommerce
DESCRIPTION:
Artemis Payment Gateway for WooCommerce
artemis-payment-gateway
Accept payment for WooCommerce orders via Stellar (both XLM and other tokens built on the Stellar Platform). No registration and No Fees.
Busha Pay Payment Gateway for WooCommerce
busha-pay
Accept cryptocurrencies through Busha Pay such as Bitcoin, Ethereum, Litecoin and Bitcoin Cash on your WooCommerce store.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Mollie Payments for WooCommerce
mollie-payments-for-woocommerce
Accept all major payment methods in WooCommerce today. Credit cards, iDEAL and more! Fast, safe and intuitive.
CoinMall Developer Profile
1 plugin · 0 total installs
How We Detect CoinMall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coinmall/images/coinmall.pngcoinmall/style.css?ver=coinmall/script.js?ver=HTML / DOM Fingerprints
data-amountdata-invoice-iddata-currencywc_coinmall_params/wp-json/wc/v3/orders//wc-api/WC_Gateway_Coinmall/[coinmall_payment_form]