Coinremitter Crypto Payment Gateway Security & Risk Analysis

wordpress.org/plugins/coinremitter-crypto-payment-gateway

Coinremitter Official Bitcoin/Altcoin Payment Gateway for WordPress. Accept Crypto Payments on your wordpress site

10 active installs v1.1.6 PHP 8.1+ WP 6.8+ Updated Dec 26, 2025
best-crypto-payment-gatewaybitcoin-apiblockchain-apicrypto-apicrypto-payment-processor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Coinremitter Crypto Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Coinremitter Crypto Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security posture of the coinremitter-crypto-payment-gateway plugin v1.1.6 presents significant concerns. While there is no recorded vulnerability history, which is a positive indicator, the static analysis reveals critical weaknesses. The most alarming finding is the presence of 8 unprotected AJAX handlers, constituting the entire attack surface. This means that any unauthenticated user can potentially trigger these actions, leading to a high risk of unauthorized access or manipulation. Furthermore, the taint analysis indicates 9 high-severity flows with unsanitized paths, suggesting a strong likelihood of cross-site scripting (XSS) or other injection vulnerabilities if these flows are not handled with extreme care. The limited number of file operations and external HTTP requests, along with the majority of SQL queries using prepared statements, are positive signs, but they are overshadowed by the critical lack of authentication checks on essential entry points. The absence of nonce and capability checks on AJAX actions, coupled with a significant portion of outputs not being properly escaped, further exacerbates the risk profile. The plugin's reliance on jQuery is standard but does not mitigate the fundamental authentication and sanitization issues.

Key Concerns

  • 8 unprotected AJAX handlers
  • 9 high severity taint flows
  • 0 nonce checks on AJAX
  • 0 capability checks
  • 57% of outputs not properly escaped
  • 12 unsanitized paths in taint analysis
Vulnerabilities
None known

Coinremitter Crypto Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Coinremitter Crypto Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
39 prepared
Unescaped Output
69
52 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
8
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

83% prepared47 total queries

Output Escaping

43% escaped121 total outputs
Data Flows
12 unsanitized

Data Flow Analysis

12 flows12 with unsanitized paths
coinremitter_wp_wallet_add (admin\coinremitter.php:73)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Coinremitter Crypto Payment Gateway Attack Surface

Entry Points8
Unprotected8

AJAX Handlers 8

authwp_ajax_coinremitter_wp_wallet_addcoinremitter-wordpress.php:57
noprivwp_ajax_coinremitter_wp_wallet_addcoinremitter-wordpress.php:58
authwp_ajax_coinremitter_wp_wallet_editcoinremitter-wordpress.php:61
noprivwp_ajax_coinremitter_wp_wallet_editcoinremitter-wordpress.php:62
authwp_ajax_coinremitter_wp_wallet_deletecoinremitter-wordpress.php:65
noprivwp_ajax_coinremitter_wp_wallet_deletecoinremitter-wordpress.php:66
authwp_ajax_store_rel_valuecoinremitter-wordpress.php:99
noprivwp_ajax_store_rel_valuecoinremitter-wordpress.php:100
WordPress Hooks 24
actionadmin_noticesadmin\coinremitter-payment-setting.php:53
actioninitcoinremitter-wordpress.php:49
actioncoinremitter_enqueue_script_admincoinremitter-wordpress.php:55
actionadmin_menucoinremitter-wordpress.php:69
actionadd_meta_boxescoinremitter-wordpress.php:74
actionupdate_optioncoinremitter-wordpress.php:77
filterwoocommerce_get_return_urlcoinremitter-wordpress.php:83
actionplugins_loadedcoinremitter-wordpress.php:84
actionwp_enqueue_scriptscoinremitter-wordpress.php:86
filterbody_classcoinremitter-wordpress.php:87
actionwc_ajax_coinremitter_webhook_datacoinremitter-wordpress.php:90
actionwc_ajax_nopriv_coinremitter_webhook_datacoinremitter-wordpress.php:91
actionwc_ajax_coinremitter_cancel_ordercoinremitter-wordpress.php:94
actionwoocommerce_order_details_after_order_tablecoinremitter-wordpress.php:97
actionparse_requestcoinremitter-wordpress.php:98
filterwoocommerce_payment_gatewayscoinremitter-wordpress.php:101
actionupdate_fiat_rate_hookcoinremitter-wordpress.php:103
actionwpcoinremitter-wordpress.php:104
filterpage_templatecoinremitter-wordpress.php:150
filtertheme_page_templatescoinremitter-wordpress.php:153
actionupgrader_process_completecoinremitter-wordpress.php:201
filtercron_schedulesfront\cron-event.php:5
actionwoocommerce_blocks_loadedfront\payment-setting.php:11
actionwoocommerce_blocks_payment_method_type_registrationfront\payment-setting.php:27

Scheduled Events 1

update_fiat_rate_hook
Maintenance & Trust

Coinremitter Crypto Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 26, 2025
PHP min version8.1
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Coinremitter Crypto Payment Gateway Alternatives

No alternatives data available yet.

Developer Profile

Coinremitter Crypto Payment Gateway Developer Profile

CoinRemitter

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Coinremitter Crypto Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coinremitter-crypto-payment-gateway/css/main.css/wp-content/plugins/coinremitter-crypto-payment-gateway/js/main.js/wp-content/plugins/coinremitter-crypto-payment-gateway/js/admin.js
Script Paths
/wp-content/plugins/coinremitter-crypto-payment-gateway/js/main.js/wp-content/plugins/coinremitter-crypto-payment-gateway/js/admin.js
Version Parameters
coinremitter-crypto-payment-gateway/css/main.css?ver=coinremitter-crypto-payment-gateway/js/main.js?ver=coinremitter-crypto-payment-gateway/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
coinremitter_payment_formcoinremitter-form-wrap
HTML Comments
<!-- coinremitter payment block setting --><!-- invoice page create --><!-- plugin activation invoice timer set --><!-- CoinRemitter Crypto Payment Gateway -->
Data Attributes
data-coinremitter-coin-iddata-coinremitter-coin-symbol
JS Globals
coinremitter_ajax_objectcoinremitter_vars
REST Endpoints
/wp-json/coinremitter/v1/create-invoice/wp-json/coinremitter/v1/get-invoice-status
Shortcode Output
[coinremitter_payment]
FAQ

Frequently Asked Questions about Coinremitter Crypto Payment Gateway