Cointopay.com CC Only Security & Risk Analysis

wordpress.org/plugins/cointopay-com-cc-only

Extends WooCommerce with card payments gateway.

50 active installs v1.3.8 PHP + WP 3.8.1+ Updated Mar 12, 2026
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cointopay.com CC Only Safe to Use in 2026?

Generally Safe

Score 100/100

Cointopay.com CC Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The cointopay-com-cc-only v1.3.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring all outputs are properly escaped, indicating a good understanding of common web vulnerabilities. There are no recorded historical vulnerabilities, which is a positive sign for the plugin's maintainability and overall security track record.

However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a substantial attack surface, as any unauthenticated user could potentially trigger these handlers. The absence of nonce checks further exacerbates this risk, making cross-site request forgery (CSRF) attacks a distinct possibility. While taint analysis did not reveal any specific unsanitized paths, the lack of proper input validation on the unprotected AJAX endpoints could still lead to unexpected behavior or vulnerabilities if combined with other factors.

In conclusion, while the plugin avoids common pitfalls like raw SQL or unescaped output, the unprotected AJAX endpoints represent a critical security weakness. The lack of any capability or nonce checks on these entry points significantly lowers its overall security score, despite its otherwise clean code practices. The absence of historical vulnerabilities is encouraging, but it does not mitigate the immediate risks posed by the exposed and unprotected AJAX functionality.

Key Concerns

  • 2 unprotected AJAX handlers
  • 0 Nonce checks on AJAX handlers
  • 0 Capability checks on AJAX handlers
Vulnerabilities
None known

Cointopay.com CC Only Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cointopay.com CC Only Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
58 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped58 total outputs
Attack Surface
2 unprotected

Cointopay.com CC Only Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_getCTPCCMerchantCoinshooks\get_merchant_coins.php:2
authwp_ajax_getCTPCCMerchantCoinshooks\get_merchant_coins.php:3
WordPress Hooks 8
actioninitclasses\wc_cointopay_cc_gateway.php:37
actionadmin_noticesclasses\wc_cointopay_cc_gateway.php:59
actionadmin_noticesclasses\wc_cointopay_cc_gateway.php:64
actionadmin_enqueue_scriptsclasses\wc_cointopay_cc_gateway.php:66
filterwoocommerce_payment_gatewayswc-cointopay-cc-only.php:19
actionplugins_loadedwc-cointopay-cc-only.php:25
actionwoocommerce_blocks_loadedwc-cointopay-cc-only.php:38
actionwoocommerce_blocks_payment_method_type_registrationwc-cointopay-cc-only.php:67
Maintenance & Trust

Cointopay.com CC Only Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version
Downloads969

Community Trust

Rating0/100
Number of ratings0
Active installs50
Alternatives

Cointopay.com CC Only Alternatives

No alternatives data available yet.

Developer Profile

Cointopay.com CC Only Developer Profile

Cointopaydev

5 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cointopay.com CC Only

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cointopay-com-cc-only/assets/js/ctp_cc_custom.js
Script Paths
/wp-content/plugins/cointopay-com-cc-only/assets/js/ctp_cc_custom.js
Version Parameters
cointopay-com-cc-only/assets/js/ctp_cc_custom.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Provides a secure way to accept crypto currencies. -->
JS Globals
ajaxurlctpcc
FAQ

Frequently Asked Questions about Cointopay.com CC Only