Cryptocurrency Payments & Donations with Copperx Security & Risk Analysis

wordpress.org/plugins/copperx

Copperx is the best plugin to accept cryptocurrency payments for your e-commerce store. We support Bitcoin, Ethereum, USDC, USDT, Binance, Coinbase, a …

10 active installs v1.8.0 PHP 5.6+ WP 5.0+ Updated Nov 30, 2024
bitcashbitcoinblockchainethereumlitecoin
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payments & Donations with Copperx Safe to Use in 2026?

Generally Safe

Score 92/100

Cryptocurrency Payments & Donations with Copperx has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "copperx" plugin version 1.8.0 exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the static analysis reveals an absence of dangerous functions, properly escaped output, and SQL queries utilizing prepared statements. The attack surface appears minimal and without publicly disclosed vulnerabilities, suggesting good development practices. The plugin also avoids bundled libraries which can sometimes introduce outdated code.

However, several areas warrant attention. The complete lack of nonce checks and capability checks across all identified entry points (even though the total count is low) is a significant concern. This means that even the single cron event could potentially be triggered or manipulated by unauthenticated users if it performs any sensitive operations or interacts with data that shouldn't be publicly accessible. While no specific taint flows were found, the absence of these checks means that any potential future vulnerability in the cron event or other code could be exploited without authentication. The plugin also performs file operations and makes external HTTP requests, which are always areas to scrutinize for potential security weaknesses, especially without accompanying authentication checks.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • File operations without explicit checks
  • External HTTP requests without explicit checks
Vulnerabilities
None known

Cryptocurrency Payments & Donations with Copperx Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cryptocurrency Payments & Donations with Copperx Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped18 total outputs
Attack Surface

Cryptocurrency Payments & Donations with Copperx Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_enqueue_scriptsclass-wc-gateway-copperx.php:78
actionadmin_enqueue_scriptsclass-wc-gateway-copperx.php:79
filterwoocommerce_order_data_store_cpt_get_orders_queryclass-wc-gateway-copperx.php:81
actionwoocommerce_api_wc_gateway_copperxclass-wc-gateway-copperx.php:82
actionadmin_noticesclass-wc-gateway-copperx.php:83
actioninitcopperx.php:48
filterwoocommerce_valid_order_statuses_for_paymentcopperx.php:50
actioncopperx_check_orderscopperx.php:51
filterwoocommerce_payment_gatewayscopperx.php:52
filterwc_order_statusescopperx.php:53
actionwoocommerce_order_details_after_order_tablecopperx.php:54
actionplugins_loadedcopperx.php:57
actionbefore_woocommerce_initcopperx.php:62
actionbefore_woocommerce_initcopperx.php:71
actionwoocommerce_blocks_loadedcopperx.php:79
actionwoocommerce_blocks_payment_method_type_registrationcopperx.php:92
filtercron_schedulescopperx.php:123

Scheduled Events 1

copperx_check_orders
Maintenance & Trust

Cryptocurrency Payments & Donations with Copperx Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedNov 30, 2024
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Cryptocurrency Payments & Donations with Copperx Developer Profile

copperxhq

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payments & Donations with Copperx

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/copperx/includes/class-wc-checkout-block-gateway-copperx.php/wp-content/plugins/copperx/copperx.php

HTML / DOM Fingerprints

Shortcode Output
<p>Copperx Reference Payment ID # <a href="<?php echo esc_html($order->get_meta('_copperx_checkout_url')); ?>" target="_blank"><?php echo esc_html($order->get_meta('_copperx_checkout_id')); ?></a></p>
FAQ

Frequently Asked Questions about Cryptocurrency Payments & Donations with Copperx