Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Security & Risk Analysis

wordpress.org/plugins/cryptopay-gateway-for-cf7

Cryptocurrency Payment Gateway Plugin for Contact Form 7 Bitcoin payments, Crypto payments, Cryptocurrency Payments, Ethereum, USDT, BTC, ETH, SOL

0 active installs v1.0.2 PHP 8.1+ WP 5.0+ Updated Jun 11, 2025
bitcoincontact-form-7cryptoethereumpayment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Safe to Use in 2026?

Generally Safe

Score 100/100

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The static analysis of the "cryptopay-gateway-for-cf7" v1.0.2 plugin reveals a generally strong security posture. The plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and properly escaping the vast majority of its output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. The presence of a nonce check, although only one, is also a positive sign. However, the taint analysis identified one flow with an unsanitized path, which warrants attention despite not being categorized as critical or high severity. This indicates a potential area where user-supplied data might not be sufficiently validated before being used, which could be exploited in certain scenarios.

The plugin's vulnerability history is clean, with no known CVEs recorded. This suggests a history of either good security development or a lack of targeted security research against this specific version. While the absence of past vulnerabilities is positive, it's important not to become complacent. The single unsanitized path in the taint analysis, coupled with the absence of capability checks, presents a potential weakness that could be exploited if an attacker can control the input to that specific path. The plugin's strengths lie in its secure handling of database operations and output, but the identified taint flow is a notable concern.

Key Concerns

  • Flow with unsanitized path identified
  • Only one nonce check present
  • No capability checks found
Vulnerabilities
None known

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Release Timeline

v1.0.2Current
Code Analysis
Analyzed Apr 16, 2026

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
26 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped28 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
panelContent (app/Gateways/AbstractGateway.php:194)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwpcf7_initapp/Gateways/AbstractGateway.php:29
actionwpcf7_after_saveapp/Gateways/AbstractGateway.php:30
filterwpcf7_editor_panelsapp/Gateways/AbstractGateway.php:31
filterwpcf7_posted_dataapp/Gateways/AbstractGateway.php:32
actionwpcf7_before_send_mailapp/Gateways/AbstractGateway.php:33
actioninitapp/Loader.php:19
actionplugins_loadedcryptopay-gateway-for-cf7.php:53
Maintenance & Trust

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 11, 2025
PHP min version8.1
Downloads391

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay Developer Profile

BeycanPress LLC

22 plugins · 240 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptopay-gateway-for-cf7/assets/js/main.js
Script Paths
/wp-content/plugins/cryptopay-gateway-for-cf7/assets/js/main.js
Version Parameters
cryptopay-gateway-for-cf7/assets/js/main.js?ver=1.0.2

HTML / DOM Fingerprints

CSS Classes
wpcf7-submithas-spinner
HTML Comments
<!-- here is fe side and adding nonce field below -->
Data Attributes
name="cf7_cp_nonce"id="cf7_cp_activate"name="cf7_cp_activate"id="cf7_cp_item_id"name="cf7_cp_item_id"id="cf7_cp_item_price"+5 more
JS Globals
window.jQuerywindow.__window._wp
Shortcode Output
<input type="hidden" name="transaction-hash" value="" /><input class="wpcf7-form-control wpcf7-submit has-spinner" type="submit" value="
FAQ

Frequently Asked Questions about Cryptocurrency Payment Gateway for Contact Form 7 by CryptoPay