Bitcoin payment for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/coinsnap-for-gravity-forms

With this Bitcoin payment plugin for Gravity Forms you can now offer products, downloads, bookings or get donations in Bitcoin right in your forms!

0 active installs v1.3.4 PHP 7.4+ WP 5.2+ Updated Mar 7, 2026
bitcoingravity-formslightningpayment-gatewaysats
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bitcoin payment for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Bitcoin payment for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "coinsnap-for-gravity-forms" v1.3.5 plugin exhibits a generally strong security posture based on the static analysis. The plugin has a small attack surface, with only two AJAX handlers and no REST API routes, shortcodes, or cron events. Crucially, all identified entry points appear to have authentication checks, which is a significant positive. The code also demonstrates good practices in SQL query handling, with 100% prepared statements, and excellent output escaping, with 98% of outputs properly escaped. Nonce and capability checks are also present, further bolstering its security.

However, a notable concern is the presence of the `unserialize` function, which, if not handled with extreme care and strict input validation, can lead to Remote Code Execution vulnerabilities. While the taint analysis reported zero flows, this doesn't entirely mitigate the inherent risk of `unserialize` if the data it processes originates from an untrusted source. The single file operation and external HTTP request, while not flagged as problematic here, represent potential areas for future investigation or hardening if their context isn't fully understood.

The plugin's vulnerability history is remarkably clean, with zero known CVEs. This suggests a commitment to security by the developers or a lack of discovered vulnerabilities over time. This, combined with the good code practices observed, paints a picture of a relatively secure plugin. The main weakness lies in the potential misuse of the `unserialize` function, which warrants careful attention.

Key Concerns

  • Dangerous function: unserialize detected
Vulnerabilities
None known

Bitcoin payment for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bitcoin payment for Gravity Forms Release Timeline

v1.3.4Current
v1.3.3
v1.3.2
v1.3.1
v1.2.1
v1.2.0
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Bitcoin payment for Gravity Forms Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
4 prepared
Unescaped Output
2
88 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$notice = unserialize($coinsnap_notice);library/Util/Notice.php:25

SQL Query Safety

100% prepared4 total queries

Output Escaping

98% escaped90 total outputs
Attack Surface

Bitcoin payment for Gravity Forms Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_coinsnap_connection_handlerclass-gf-coinsnap.php:37
authwp_ajax_btcpay_server_apiurl_handlerclass-gf-coinsnap.php:38
WordPress Hooks 11
actionadmin_enqueue_scriptsclass-gf-coinsnap.php:36
actiongform_validationclass-gf-coinsnap.php:41
actiontemplate_redirectclass-gf-coinsnap.php:45
actionwpclass-gf-coinsnap.php:393
filtergform_disable_post_creationclass-gf-coinsnap.php:450
filtergform_disable_notificationclass-gf-coinsnap.php:451
actionadmin_initcoinsnap-for-gravity-forms.php:34
actiongform_loadedcoinsnap-for-gravity-forms.php:35
actionadmin_noticescoinsnap-for-gravity-forms.php:39
actioninitcoinsnap-for-gravity-forms.php:65
filterrequestcoinsnap-for-gravity-forms.php:72
Maintenance & Trust

Bitcoin payment for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 7, 2026
PHP min version7.4
Downloads882

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bitcoin payment for Gravity Forms Developer Profile

Coinsnap

14 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bitcoin payment for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coinsnap-for-gravity-forms/coinsnap-gf.php/wp-content/plugins/coinsnap-for-gravity-forms/class-gf-coinsnap.php/wp-content/plugins/coinsnap-for-gravity-forms/library/ Coinsnap/client/Store.php/wp-content/plugins/coinsnap-for-gravity-forms/library/ Coinsnap/client/BTCPayApiAuthorization.php

HTML / DOM Fingerprints

Data Attributes
coinsnap-for-gravity-forms-btcpay-settings-callback
FAQ

Frequently Asked Questions about Bitcoin payment for Gravity Forms