Cryptocurrency Payment Gateway for WPForms by CryptoPay Security & Risk Analysis

wordpress.org/plugins/cryptopay-gateway-for-wpforms

Cryptocurrency Payment Gateway for WPForms, Cryptocurrency payments for WordPress, Bitcoin payments, Ethereum, Crypto payments, USDT, BTC, ETH, SOL

0 active installs v1.0.2 PHP 8.1+ WP 5.0+ Updated Aug 14, 2025
bitcoincryptoethereumpaymentwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Gateway for WPForms by CryptoPay Safe to Use in 2026?

Generally Safe

Score 100/100

Cryptocurrency Payment Gateway for WPForms by CryptoPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The plugin 'cryptopay-gateway-for-wpforms' version 1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and 100% proper output escaping are commendable security practices. Furthermore, the lack of any recorded vulnerabilities or CVEs suggests a history of responsible development and maintenance.

However, several concerning signals are present. The complete absence of nonce checks and capability checks, particularly when combined with the presence of file operations and an unknown number of entry points (even if the count is zero in this snapshot, the potential for future additions exists), raises significant concerns. A lack of authorization checks on any potential entry points could lead to privilege escalation or unauthorized data manipulation if new attack vectors are introduced or if the current count of zero entry points is a temporary state. The taint analysis showing zero unsanitized paths is positive, but this must be viewed in conjunction with the missing security controls.

In conclusion, while the plugin demonstrates good coding hygiene in areas like SQL and output handling, the fundamental lack of nonce and capability checks represents a significant security weakness. This oversight could leave the plugin vulnerable to various attacks if any form of user-writable data or executable code is processed without proper authorization. The absence of historical vulnerabilities is a positive sign, but it does not negate the inherent risks posed by the current codebase's security control deficiencies.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • File operations present without explicit auth checks
Vulnerabilities
None known

Cryptocurrency Payment Gateway for WPForms by CryptoPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cryptocurrency Payment Gateway for WPForms by CryptoPay Release Timeline

v1.0.2Current
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Cryptocurrency Payment Gateway for WPForms by CryptoPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped54 total outputs
Attack Surface

Cryptocurrency Payment Gateway for WPForms by CryptoPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
filterwpforms_builder_fields_optionsapp/Field.php:82
filterwpforms_field_new_requiredapp/Field.php:86
actionwpforms_builder_enqueuesapp/Field.php:88
filterwpforms_builder_stringsapp/Field.php:89
filterwpforms_builder_field_button_attributesapp/Field.php:90
filterwpforms_frontend_foot_submit_classesapp/Field.php:91
filterwpforms_field_new_display_duplicate_buttonapp/Field.php:92
filterwpforms_field_preview_display_duplicate_buttonapp/Field.php:93
actioninitapp/Loader.php:18
filterwpforms_payments_availableapp/Payments.php:55
actionwpforms_payments_panel_contentapp/Payments.php:56
actionwpforms_payments_panel_sidebarapp/Payments.php:57
filterwpforms_admin_education_addons_item_base_display_single_addon_hideapp/Payments.php:58
actionwpforms_process_initial_errorsapp/Process.php:22
actionwpforms_process_completeapp/Process.php:23
filterwpforms_settings_defaultsapp/Settings.php:16
actionplugins_loadedcryptopay-gateway-for-wpforms.php:52
filterwpforms_integrations_availablecryptopay-gateway-for-wpforms.php:59
filterwpforms_db_payments_value_validator_get_allowed_gatewayswpforms/CryptoPay.php:33
filterwpforms_admin_payments_views_single_gateway_transaction_linkwpforms/CryptoPay.php:38
filterwpforms_admin_payments_views_single_gateway_dashboard_linkwpforms/CryptoPay.php:45
filterwpforms_helpers_templates_include_html_argswpforms/CryptoPay.php:52
Maintenance & Trust

Cryptocurrency Payment Gateway for WPForms by CryptoPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 14, 2025
PHP min version8.1
Downloads311

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cryptocurrency Payment Gateway for WPForms by CryptoPay Developer Profile

BeycanPress LLC

22 plugins · 240 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Gateway for WPForms by CryptoPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptopay-gateway-for-wpforms/assets/images/icon.svg
Script Paths
/wp-content/plugins/cryptopay-gateway-for-wpforms/assets/js/admin.js
Version Parameters
cryptopay-gateway-for-wpforms/assets/js/admin.js?ver=cryptopay-gateway-for-wpforms.php?ver=

HTML / DOM Fingerprints

CSS Classes
wpforms-field-cryptopay
Data Attributes
data-field-id="cryptopay"data-encrypt-nonce="true"
JS Globals
wpforms_builder_cryptopay
FAQ

Frequently Asked Questions about Cryptocurrency Payment Gateway for WPForms by CryptoPay