Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Security & Risk Analysis

wordpress.org/plugins/cryptopay-withdrawal-for-dokan

Cryptocurrency Payment Withdrawal Method for Dokan, Cryptocurrency payments for WooCommerce, Bitcoin payments, Crypto payments, USDT, BTC, ETH, SOL

10 active installs v1.0.8 PHP 8.1+ WP 5.0+ Updated Unknown
bitcoincryptocurrencydokanethereumpayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Safe to Use in 2026?

Generally Safe

Score 100/100

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "cryptopay-withdrawal-for-dokan" plugin, version 1.0.8, exhibits a strong security posture based on the provided static analysis. There are no identified critical or high-severity code signals such as dangerous functions, raw SQL queries, or taint flows. The plugin also demonstrates good practices in output escaping, with a very high percentage of outputs being properly sanitized. The absence of any known CVEs, past or present, further reinforces its current security standing. However, a notable concern is the complete lack of capability checks in the code analysis. This could imply that any entry point, though currently limited in number, might not be adequately protected against unauthorized access if new entry points are introduced or if existing ones have implicit authorization loopholes.

While the plugin's current attack surface is zero and all identified code signals are positive, the absence of capability checks represents a potential weakness. The zero taint analysis and no known vulnerabilities are excellent indicators, suggesting the developers have a good understanding of secure coding. However, the lack of explicit capability checks means that the plugin relies on other components or WordPress's default behavior for authorization, which might not always be sufficient. In conclusion, the plugin appears to be well-coded with minimal immediate risks, but the lack of capability checks is a significant oversight that warrants attention for future development and auditing.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Attack Surface

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterdokan_withdraw_methodsclasses\DokanCryptoPayWithdrawal.php:54
filterdokan_withdraw_method_iconclasses\DokanCryptoPayWithdrawal.php:55
filterdokan_store_profile_settings_argsclasses\DokanCryptoPayWithdrawal.php:56
filterdokan_withdraw_withdrawable_payment_methodsclasses\DokanCryptoPayWithdrawal.php:57
filterdokan_get_seller_active_withdraw_methodsclasses\DokanCryptoPayWithdrawal.php:58
filterdokan_payment_settings_required_fieldsclasses\DokanCryptoPayWithdrawal.php:59
filterdokan_withdraw_method_additional_infoclasses\DokanCryptoPayWithdrawal.php:60
actioninitcryptopay-withdrawal-for-dokan.php:37
actionplugins_loadedcryptopay-withdrawal-for-dokan.php:41
actionadmin_noticescryptopay-withdrawal-for-dokan.php:45
actionadmin_noticescryptopay-withdrawal-for-dokan.php:57
actionadmin_enqueue_scriptscryptopay-withdrawal-for-dokan.php:71
actionadmin_footercryptopay-withdrawal-for-dokan.php:80
actionadmin_noticescryptopay-withdrawal-for-dokan.php:96
Maintenance & Trust

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version8.1
Downloads862

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay Developer Profile

BeycanPress LLC

16 plugins · 260 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptopay-withdrawal-for-dokan/assets/js/admin.js
Script Paths
/wp-content/plugins/cryptopay-withdrawal-for-dokan/assets/js/admin.js
Version Parameters
cryptopay-withdrawal-for-dokan/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-loading
JS Globals
DokanCryptoPay
REST Endpoints
/wp-json/dokan/v1/withdraw/
FAQ

Frequently Asked Questions about Cryptocurrency Payment Withdrawal Method for Dokan by CryptoPay