Coinbase Commerce – Crypto Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/commerce-coinbase-for-woocommerce

Coinbase Commerce is the best crypto gateway, allows users to checkout with popular crypto currencies such as Bitcoin, Bitcoin Cash, DAI, Ethereum, Do …

1K active installs v1.6.6 PHP 5.2.4+ WP 4.9+ Updated Dec 23, 2025
bitcoincoinbasecryptoethereumlitecoin
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMar 23, 2026
Safety Verdict

Is Coinbase Commerce – Crypto Gateway for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

Coinbase Commerce – Crypto Gateway for WooCommerce is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Mar 23, 2026Updated 4mo ago
Risk Assessment

The 'commerce-coinbase-for-woocommerce' plugin, version 1.6.6, demonstrates a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are strong indicators of responsible development and maintenance. The plugin also shows positive signs in its code, with no dangerous functions, all SQL queries using prepared statements, and no reported taint flows. This suggests a low risk of common vulnerabilities like SQL injection or remote code execution stemming from these areas.

However, there are areas that warrant attention. The plugin has an unprotected REST API route, which represents a potential entry point for attackers if not properly secured by an application-level firewall or other security measures. Additionally, a significant portion of its output (33%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. The lack of nonce and capability checks on AJAX handlers and REST API routes respectively is a concern, as these are fundamental WordPress security mechanisms designed to prevent unauthorized actions and ensure only authorized users can access certain functionalities. The presence of a bundled library (Freemius v1.0) also carries a potential risk if it's outdated or contains its own vulnerabilities.

Overall, while the plugin benefits from a lack of historical vulnerabilities and good SQL practices, the identified potential for XSS, the unprotected REST API endpoint, and the absence of core WordPress security checks like nonces and capability checks introduce measurable risks. Addressing these specific concerns would significantly strengthen the plugin's security.

Key Concerns

  • Unprotected REST API route
  • Unescaped output identified
  • Missing nonce checks on AJAX
  • Missing capability checks on REST API
  • Bundled Freemius v1.0 library
Vulnerabilities
1 published

Coinbase Commerce – Crypto Gateway for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-25396medium · 5.3Missing Authorization

Coinbase Commerce – Crypto Gateway for WooCommerce <= 1.6.6 - Missing Authorization

Mar 23, 2026Unpatched
Version History

Coinbase Commerce – Crypto Gateway for WooCommerce Release Timeline

v1.6.71 CVE
v1.6.51 CVE
v1.6.41 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.6.11 CVE
v1.6.01 CVE
v1.5.01 CVE
v1.4.141 CVE
v1.4.131 CVE
v1.4.121 CVE
v1.4.111 CVE
v1.4.101 CVE
v1.4.91 CVE
v1.4.81 CVE
v1.4.71 CVE
v1.4.61 CVE
v1.4.51 CVE
v1.4.41 CVE
v1.4.31 CVE
Code Analysis
Analyzed Mar 16, 2026

Coinbase Commerce – Crypto Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

67% escaped3 total outputs
Attack Surface

Coinbase Commerce – Crypto Gateway for WooCommerce Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/ccfwc/v1/complete-paymentincludes\webhook.php:21
WordPress Hooks 10
actionwp_enqueue_scriptscoinbase-gateway-for-woocommerce.php:87
actionplugins_loadedcoinbase-gateway-for-woocommerce.php:421
actionadmin_noticescoinbase-gateway-for-woocommerce.php:423
filterwoocommerce_payment_gatewayscoinbase-gateway-for-woocommerce.php:434
actionadmin_enqueue_scriptscoinbase-gateway-for-woocommerce.php:440
filterplugin_row_metacoinbase-gateway-for-woocommerce.php:459
actionwoocommerce_blocks_payment_method_type_registrationcoinbase-gateway-for-woocommerce.php:483
actionadmin_noticescoinbase-gateway-for-woocommerce.php:511
actionadmin_post_ccwc_hide_noticecoinbase-gateway-for-woocommerce.php:512
actionrest_api_initincludes\webhook.php:11
Maintenance & Trust

Coinbase Commerce – Crypto Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 23, 2025
PHP min version5.2.4
Downloads55K

Community Trust

Rating84/100
Number of ratings26
Active installs1K
Developer Profile

Coinbase Commerce – Crypto Gateway for WooCommerce Developer Profile

CoderPress

9 plugins · 4K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect Coinbase Commerce – Crypto Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/commerce-coinbase-for-woocommerce/assets/js/checkout.js/wp-content/plugins/commerce-coinbase-for-woocommerce/assets/css/checkout.css
Script Paths
https://commerce.coinbase.com/v1/checkout.js
Version Parameters
commerce-coinbase-for-woocommerce/assets/js/checkout.js?ver=commerce-coinbase-for-woocommerce/assets/css/checkout.css?ver=

HTML / DOM Fingerprints

JS Globals
Coinbase
FAQ

Frequently Asked Questions about Coinbase Commerce – Crypto Gateway for WooCommerce