Cryptocurrency Payment Gateway for MemberPress by CryptoPay Security & Risk Analysis

wordpress.org/plugins/cryptopay-gateway-for-memberpress

Cryptocurrency Payment Gateway for MemberPress, Cryptocurrency payments for WordPress, Bitcoin payments, Crypto payments, USDT, BTC, ETH, SOL

10 active installs v1.0.7 PHP 8.1+ WP 5.0+ Updated May 22, 2025
bitcoincryptocurrencyethereummemberpresspayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Gateway for MemberPress by CryptoPay Safe to Use in 2026?

Generally Safe

Score 100/100

Cryptocurrency Payment Gateway for MemberPress by CryptoPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The cryptopay-gateway-for-memberpress plugin, version 1.0.7, appears to have a strong static security posture. The analysis shows no identified attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, there are no dangerous functions, raw SQL queries, file operations, external HTTP requests, or identified taint flows with unsanitized paths. This indicates that the developers have followed good security practices in code development, particularly in sanitizing input and preventing common web vulnerabilities.

However, the complete absence of nonce checks and capability checks, coupled with a lack of explicit permission callbacks for any potential REST API routes (even though none are listed), raises a concern. While the current analysis shows no entry points, a future update or a slight modification to the plugin's functionality without these checks could introduce significant security risks, especially if new AJAX actions or REST API endpoints are added. The lack of vulnerability history is a positive sign, suggesting a history of secure development or a lack of prior discovery, but it does not negate the potential risks associated with missing fundamental security controls like nonces and capability checks.

In conclusion, the plugin exhibits strong foundational security practices in its current state, with no immediate critical vulnerabilities detected. The primary weakness lies in the potential for future vulnerabilities due to the absence of essential security checks (nonces, capability checks) that could be exploited if new entry points are introduced or if the existing code base is modified without these safeguards. This makes it crucial for developers to implement these standard WordPress security measures in any future updates.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Cryptocurrency Payment Gateway for MemberPress by CryptoPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cryptocurrency Payment Gateway for MemberPress by CryptoPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped30 total outputs
Attack Surface

Cryptocurrency Payment Gateway for MemberPress by CryptoPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitclasses\lite\MeprCryptoPayLiteCtrl.php:25
actioninitclasses\pro\MeprCryptoPayCtrl.php:25
actioninitcryptopay-gateway-for-memberpress.php:77
actionplugins_loadedcryptopay-gateway-for-memberpress.php:81
actionadmin_noticescryptopay-gateway-for-memberpress.php:84
filtermepr-gateway-pathscryptopay-gateway-for-memberpress.php:103
filtermepr-ctrls-pathscryptopay-gateway-for-memberpress.php:104
actionadmin_noticescryptopay-gateway-for-memberpress.php:133
Maintenance & Trust

Cryptocurrency Payment Gateway for MemberPress by CryptoPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 22, 2025
PHP min version8.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cryptocurrency Payment Gateway for MemberPress by CryptoPay Developer Profile

BeycanPress LLC

16 plugins · 260 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Gateway for MemberPress by CryptoPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptopay-gateway-for-memberpress/assets/images/icon.png
Version Parameters
cryptopay-gateway-for-memberpress/assets/images/icon.png?ver=

HTML / DOM Fingerprints

CSS Classes
mepr-cryptopay-notice-wrap
HTML Comments
<!-- CryptoPay Gateway for MemberPress: This plugin requires MemberPress to work. You can buy MemberPress by <a href="https://memberpress.com/" target="_blank">clicking here</a>. --><!-- CryptoPay Gateway for MemberPress: This plugin is an extra feature plugin so it cannot do anything on its own. It needs CryptoPay to work. You can buy CryptoPay by <a href="https://beycanpress.com/product/cryptopay-all-in-one-cryptocurrency-payments-for-wordpress/?utm_source=wp_org_addons&utm_medium=memberpress" target="_blank">clicking here</a>. -->
FAQ

Frequently Asked Questions about Cryptocurrency Payment Gateway for MemberPress by CryptoPay