
Crypto QR Code WP Security & Risk Analysis
wordpress.org/plugins/crypto-qr-code-wpAdd cryptocurrencies QR code donate with tooltip.
Is Crypto QR Code WP Safe to Use in 2026?
Generally Safe
Score 100/100Crypto QR Code WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The crypto-qr-code-wp plugin v1.0.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and has no known historical vulnerabilities, indicating a generally stable and secure development history. The static analysis also shows a small attack surface with no unprotected entry points and a limited number of file operations and external HTTP requests. However, a significant concern arises from the complete lack of output escaping across all 12 identified output points. This presents a substantial risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website if user-supplied data is not properly sanitized before being displayed. Additionally, while the plugin has capability checks, the absence of nonce checks on any entry points, including the single shortcode, is a notable weakness. This could allow for cross-site request forgery (CSRF) attacks. The lack of taint analysis results also means potential vulnerabilities in data flow might have been missed.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL handling, the critical deficiency in output escaping and the absence of nonce checks introduce significant security risks. The developer should prioritize addressing the unescaped output to mitigate XSS vulnerabilities and implement nonce checks to prevent CSRF attacks. The limited scope of the static analysis and the absence of taint analysis further suggest that a more thorough review might be beneficial.
Key Concerns
- 0% output escaping
- 0 nonce checks
Crypto QR Code WP Security Vulnerabilities
Crypto QR Code WP Release Timeline
Crypto QR Code WP Code Analysis
Bundled Libraries
Output Escaping
Crypto QR Code WP Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Crypto QR Code WP Maintenance & Trust
Maintenance Signals
Community Trust
Crypto QR Code WP Alternatives
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Crypto Converter ⚡ Widget
crypto-converter-widget
Effortless ❤️ crypto/fiat conversion: ⚡ live, secure, fast, customizable WP 📟 widget—no API keys needed, completely free!
BinancePay Checkout for WooCommerce
binance-pay
Binance Pay Checkout for WooCommerce.
Crypto QR Code WP Developer Profile
3 plugins · 1K total installs
How We Detect Crypto QR Code WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crypto-qr-code-wp/assets/js/script.js/wp-content/plugins/crypto-qr-code-wp/assets/css/style.css/wp-content/plugins/crypto-qr-code-wp/assets/js/script.jscrypto-qr-code-wp/assets/js/script.js?ver=crypto-qr-code-wp/assets/css/style.css?ver=HTML / DOM Fingerprints
cqcw-blockcqcw-block__labelcqcw-block__buttoncqcw-block__dialogcqcw-block__dialog-headingcqcw-block__dialog-contentcqcw-block__button-closeid="{$label}_{$address}_{$random_num}"<span class="cqcw-block"><label class="cqcw-block__label"><a href="#{$label}_{$address}_{$random_num}" class="cqcw-block__button"><em id="{$label}_{$address}_{$random_num}" class="cqcw-block__dialog">