
CryptoCloud – Crypto Payment Gateway Security & Risk Analysis
wordpress.org/plugins/cryptocloud-crypto-payment-gatewayCryptoCloud - cryptocurrency payment system for business. We offer to you a possibility to accept payments worldwide in 40 cryptocurrencies.
Is CryptoCloud – Crypto Payment Gateway Safe to Use in 2026?
Mostly Safe
Score 78/100CryptoCloud – Crypto Payment Gateway is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of the 'cryptocloud-crypto-payment-gateway' plugin v2.3.2 reveals a seemingly strong security posture in some areas. The absence of any identified dangerous functions, SQL queries using prepared statements, properly escaped output, and a lack of taint flows with unsanitized paths are positive indicators. Furthermore, the plugin has no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks, which significantly reduces the attack surface.
However, there are significant concerns. The plugin has a history of vulnerabilities, with one medium severity CVE currently unpatched. The common vulnerability type of 'Missing Authorization' historically is a red flag, suggesting a recurring weakness that attackers may exploit. The lack of any capability checks or nonce checks, coupled with the presence of file operations and external HTTP requests, indicates potential avenues for exploitation if authorization is not correctly implemented for these actions. The unpatched vulnerability, in particular, presents an immediate and exploitable risk.
In conclusion, while the plugin demonstrates good practices in areas like prepared statements and output escaping, the historical pattern of missing authorization vulnerabilities and the presence of an unpatched CVE, along with the absence of critical security checks like capability and nonce checks, present a notable risk. The security posture is a mix of strengths and significant weaknesses that require immediate attention, particularly regarding the unpatched vulnerability and the recurring authorization issues.
Key Concerns
- Unpatched medium CVE
- Historical missing authorization vulnerabilities
- No nonce checks
- No capability checks
CryptoCloud – Crypto Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CryptoCloud - Crypto Payment Gateway <= 2.1.2 - Missing Authorization
CryptoCloud – Crypto Payment Gateway Code Analysis
Output Escaping
CryptoCloud – Crypto Payment Gateway Attack Surface
WordPress Hooks 5
Maintenance & Trust
CryptoCloud – Crypto Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
CryptoCloud – Crypto Payment Gateway Alternatives
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
OxaPay Crypto Payment Gateway for Easy Digital Downloads
oxapay-payment-gateway-for-easy-digital-downloads
Accept cryptocurrency payments in Easy Digital Downloads using a secure and reliable gateway.
OxaPay Crypto Payment Gateway: Accept Bitcoin Payments
oxapay
Secure crypto payment plugin for WordPress
Payid19 Crypto Payment Gateway
payid19-com-payment-gateway
-Crypto Payment Gateway you can accept USDT, Bitcoin, Litecoin, Ethereum, Bnb and TRX stable coins and withdraw as USDT.
OxaPay Crypto Payment Gateway for Paid Memberships Pro
oxapay-crypto-gateway-for-paid-memberships-pro
Accept cryptocurrency payments in Paid Memberships Pro using a secure and reliable gateway.
CryptoCloud – Crypto Payment Gateway Developer Profile
1 plugin · 400 total installs
How We Detect CryptoCloud – Crypto Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocloud-crypto-payment-gateway/assets/css/cryptocloud-admin.css/wp-content/plugins/cryptocloud-crypto-payment-gateway/assets/js/cryptocloud-admin.js/wp-content/plugins/cryptocloud-crypto-payment-gateway/assets/js/cryptocloud-checkout.jsHTML / DOM Fingerprints
cryptocloud-admin-settingsdata-cryptocloud-apikeydata-cryptocloud-merchant-iddata-cryptocloud-webhook-secretcryptocloud_admin_params/wp-json/cryptocloud/v1/settings