
CoinPayments.net Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/coinpayments-payment-gateway-for-woocommerceThis plugin implements a payment gateway for WooCommerce to let buyers pay with Bitcoin, Litecoin, Ripple, and other cryptocurrencies via CoinPayments …
Is CoinPayments.net Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 95/100CoinPayments.net Payment Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin exhibits a concerning security posture primarily due to a significant lack of input validation and authorization checks, despite a clean taint analysis and no raw SQL queries. The static analysis reveals a single unprotected REST API route, which represents a direct entry point for potential attacks. Furthermore, none of the identified outputs are properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these outputs. The vulnerability history shows a past critical vulnerability related to deserialization, indicating a potential for complex and severe exploits if similar weaknesses are re-introduced. While the plugin demonstrates good practices in avoiding dangerous functions and utilizing prepared statements for SQL, the unprotected API route and poor output escaping are significant weaknesses that could be exploited. The absence of nonce and capability checks on the identified entry point is a critical oversight.
Key Concerns
- Unprotected REST API route
- No output escaping
- No nonce checks
- No capability checks
- Past critical deserialization CVE
CoinPayments.net Payment Gateway for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CoinPayments.net Payment Gateway for WooCommerce <= 1.0.17 - Unauthenticated PHP Object Injection
CoinPayments.net Payment Gateway for WooCommerce Code Analysis
Output Escaping
CoinPayments.net Payment Gateway for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
CoinPayments.net Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CoinPayments.net Payment Gateway for WooCommerce Alternatives
WP Faucet Direct
wp-faucet-direct
With WP Faucet Direct you can create your direct payment faucet in a simple way in your WordPress page by simply adding a shortcode in the section of …
GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms
gf-gourl-add-on
This plugin enables you to use the GoUrl.io payment gateway and accept bitcoin and other altcoins directly on your Gravity Forms powered custom forms …
ALFAcoins for WooCommerce
alfacoins-for-woocommerce
Accept all major cryptocurrencies like Bitcoin, Ethereum, TRC-20 & ERC-20 Tether, TRX, Litecoin, XRP with ALFAcoins plugin for WooCommerce.
Send a Wow!
send-a-wow-dogecoin-donation
Send a Wow sets a donation button for cryptocoins like dogecoin, bitcoin and litecoin under every article in your blog.
CoinMall
coinmall
Accept cryptocurrency on your WooCommerce stores through CoinMall.com
CoinPayments.net Payment Gateway for WooCommerce Developer Profile
1 plugin · 1K total installs
How We Detect CoinPayments.net Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coinpayments-payment-gateway-for-woocommerce/assets/css/coinpayments.css/wp-content/plugins/coinpayments-payment-gateway-for-woocommerce/assets/js/coinpayments.js/wp-content/plugins/coinpayments-payment-gateway-for-woocommerce/assets/js/coinpayments.jscoinpayments-payment-gateway-for-woocommerce/assets/css/coinpayments.css?ver=coinpayments-payment-gateway-for-woocommerce/assets/js/coinpayments.js?ver=HTML / DOM Fingerprints
coinpayments_payment_formdata-coinpayments-currencydata-coinpayments-amountcoinpayments_vars/wp-json/coinpayments/v1/process