CryptAPI Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/cryptapi-payment-gateway-for-woocommerce

Accept cryptocurrency payments on your WooCommerce website

300 active installs v5.1.4 PHP 7.2+ WP 5.8+ Updated Oct 2, 2025
cryptocrypto-paymentspaymentpayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CryptAPI Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CryptAPI Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The cryptapi-payment-gateway-for-woocommerce plugin version 5.1.4 exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions, raw SQL queries, and unsanitized taint flows. The plugin also demonstrates good practices with a high percentage of properly escaped output and the presence of nonce and capability checks on its entry points. The limited attack surface, with no unprotected AJAX handlers or REST API routes, further contributes to its security. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting consistent security focus from the developers.

Despite the positive findings, there are minor areas for consideration. The presence of two cron events, while not explicitly stated as unprotected, represents potential entry points that warrant careful review to ensure they are adequately secured. Similarly, the single external HTTP request, if not properly validated or sanitized, could introduce risks. While the overall security is good, a thorough audit of the two cron events and the external HTTP request would further solidify its security profile.

Key Concerns

  • Unprotected entry points
  • Unsanitized taint flows
  • Raw SQL queries without prepare
  • Missing nonce checks on AJAX
  • Unescaped output
  • Potential risk from external HTTP requests
  • Cron events as potential entry points
Vulnerabilities
None known

CryptAPI Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CryptAPI Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
205 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

89% escaped231 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<CryptAPI> (controllers\CryptAPI.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CryptAPI Payment Gateway for WooCommerce Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/cryptapi/v1/get-minimumCryptAPI.php:107
POST/wp-json/cryptapi/v1/update-coinCryptAPI.php:112
WordPress Hooks 20
actionwoocommerce_blocks_enqueue_checkout_block_scripts_afterblocks\CryptAPI.php:39
actionwcs_create_pending_renewalcontrollers\CryptAPI.php:66
actioncryptapi_cronjobcontrollers\CryptAPI.php:73
actionwoocommerce_cart_calculate_feescontrollers\CryptAPI.php:75
actionwoocommerce_checkout_update_order_reviewcontrollers\CryptAPI.php:77
actionwp_footercontrollers\CryptAPI.php:79
actionwoocommerce_email_order_detailscontrollers\CryptAPI.php:81
filterwoocommerce_my_account_my_orders_actionscontrollers\CryptAPI.php:83
actionwoocommerce_admin_order_data_after_order_detailscontrollers\CryptAPI.php:85
actionadmin_post_cryptapi_refresh_coinscontrollers\CryptAPI.php:87
actioninitCryptAPI.php:42
actionplugins_loadedCryptAPI.php:51
actionadmin_noticesCryptAPI.php:53
actionadmin_noticesCryptAPI.php:60
filtercron_schedulesCryptAPI.php:76
actionbefore_woocommerce_initCryptAPI.php:97
actionrest_api_initCryptAPI.php:106
actioninitInitialize.php:10
filterwoocommerce_payment_gatewaysRegister.php:14
actionwoocommerce_blocks_payment_method_type_registrationRegister.php:18

Scheduled Events 2

cryptapi_cronjob
cryptapi_cronjob
Maintenance & Trust

CryptAPI Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 2, 2025
PHP min version7.2
Downloads24K

Community Trust

Rating74/100
Number of ratings9
Active installs300
Developer Profile

CryptAPI Payment Gateway for WooCommerce Developer Profile

CryptAPI

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CryptAPI Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptapi-payment-gateway-for-woocommerce/blocks/dist/payment-gateway.asset.php/wp-content/plugins/cryptapi-payment-gateway-for-woocommerce/blocks/dist/payment-gateway.js/wp-content/plugins/cryptapi-payment-gateway-for-woocommerce/assets/js/admin.js/wp-content/plugins/cryptapi-payment-gateway-for-woocommerce/assets/css/admin.css
Script Paths
cryptapi-payment-gateway-for-woocommerce/blocks/dist/payment-gateway.js
Version Parameters
cryptapi-payment-gateway-for-woocommerce/blocks/dist/payment-gateway.asset.php?ver=cryptapi-payment-gateway-for-woocommerce/blocks/dist/payment-gateway.js?ver=cryptapi-payment-gateway-for-woocommerce/assets/js/admin.js?ver=cryptapi-payment-gateway-for-woocommerce/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
cryptapi_settings
Data Attributes
data-cryptapi-coindata-cryptapi-amountdata-cryptapi-addressdata-cryptapi-pricedata-cryptapi-key
JS Globals
window.wc_cryptapi_payment_gateway_params
REST Endpoints
/cryptapi/v1/get-minimum/cryptapi/v1/update-coin
FAQ

Frequently Asked Questions about CryptAPI Payment Gateway for WooCommerce