
Coinremitter Crypto Payment Gateway Security & Risk Analysis
wordpress.org/plugins/coinremitter-crypto-payment-gatewayCoinremitter Official Bitcoin/Altcoin Payment Gateway for WordPress. Accept Crypto Payments on your wordpress site
Is Coinremitter Crypto Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100Coinremitter Crypto Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the coinremitter-crypto-payment-gateway plugin v1.1.6 presents significant concerns. While there is no recorded vulnerability history, which is a positive indicator, the static analysis reveals critical weaknesses. The most alarming finding is the presence of 8 unprotected AJAX handlers, constituting the entire attack surface. This means that any unauthenticated user can potentially trigger these actions, leading to a high risk of unauthorized access or manipulation. Furthermore, the taint analysis indicates 9 high-severity flows with unsanitized paths, suggesting a strong likelihood of cross-site scripting (XSS) or other injection vulnerabilities if these flows are not handled with extreme care. The limited number of file operations and external HTTP requests, along with the majority of SQL queries using prepared statements, are positive signs, but they are overshadowed by the critical lack of authentication checks on essential entry points. The absence of nonce and capability checks on AJAX actions, coupled with a significant portion of outputs not being properly escaped, further exacerbates the risk profile. The plugin's reliance on jQuery is standard but does not mitigate the fundamental authentication and sanitization issues.
Key Concerns
- 8 unprotected AJAX handlers
- 9 high severity taint flows
- 0 nonce checks on AJAX
- 0 capability checks
- 57% of outputs not properly escaped
- 12 unsanitized paths in taint analysis
Coinremitter Crypto Payment Gateway Security Vulnerabilities
Coinremitter Crypto Payment Gateway Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Coinremitter Crypto Payment Gateway Attack Surface
AJAX Handlers 8
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
Coinremitter Crypto Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Coinremitter Crypto Payment Gateway Alternatives
No alternatives data available yet.
Coinremitter Crypto Payment Gateway Developer Profile
1 plugin · 10 total installs
How We Detect Coinremitter Crypto Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coinremitter-crypto-payment-gateway/css/main.css/wp-content/plugins/coinremitter-crypto-payment-gateway/js/main.js/wp-content/plugins/coinremitter-crypto-payment-gateway/js/admin.js/wp-content/plugins/coinremitter-crypto-payment-gateway/js/main.js/wp-content/plugins/coinremitter-crypto-payment-gateway/js/admin.jscoinremitter-crypto-payment-gateway/css/main.css?ver=coinremitter-crypto-payment-gateway/js/main.js?ver=coinremitter-crypto-payment-gateway/js/admin.js?ver=HTML / DOM Fingerprints
coinremitter_payment_formcoinremitter-form-wrap<!-- coinremitter payment block setting --><!-- invoice page create --><!-- plugin activation invoice timer set --><!-- CoinRemitter Crypto Payment Gateway -->data-coinremitter-coin-iddata-coinremitter-coin-symbolcoinremitter_ajax_objectcoinremitter_vars/wp-json/coinremitter/v1/create-invoice/wp-json/coinremitter/v1/get-invoice-status[coinremitter_payment]