
Web3 Crypto Payments by DePay for WooCommerce Security & Risk Analysis
wordpress.org/plugins/depay-payments-for-woocommerceAccept Web3 Crypto Payments. Supports various tokens, blockchains and wallets. MetaMask, Phantom, USDC, USDT, ETH, SOL, BSC, POL, xDAI…
Is Web3 Crypto Payments by DePay for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Web3 Crypto Payments by DePay for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The depay-payments-for-woocommerce plugin v3.0.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, output escaping, and file operations, with no critical or high-severity vulnerabilities found in static analysis taint flows. The plugin also shows a commitment to addressing past security issues, as indicated by the absence of currently unpatched CVEs. However, a significant concern arises from the REST API routes, where half of them lack proper permission callbacks, exposing a considerable attack surface to unauthorized access.
The vulnerability history, while currently clean, has previously shown a medium-severity issue related to missing authorization. This pattern, combined with the current lack of permission checks on REST API routes, suggests a recurring weakness in access control for certain plugin functionalities. While the code signals for dangerous functions, unescaped output, and file operations are positive, the unprotected REST API endpoints present a tangible risk of unauthorized data manipulation or access.
In conclusion, the plugin has strengths in its robust handling of core coding practices like SQL and output sanitation. Nevertheless, the presence of unprotected REST API endpoints is a notable security weakness that requires immediate attention. The historical medium-severity vulnerability also serves as a reminder of the potential for authorization bypasses. Addressing the unprotected REST API routes should be the top priority for improving the plugin's overall security.
Key Concerns
- REST API routes without permission callbacks
- No nonce checks on AJAX handlers
- Historically medium severity vulnerability
Web3 Crypto Payments by DePay for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Web3 Cryptocurrency Payments by DePay for WooCommerce <= 2.12.17 - Missing Authorization to Information Exposure
Web3 Crypto Payments by DePay for WooCommerce Release Timeline
Web3 Crypto Payments by DePay for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Web3 Crypto Payments by DePay for WooCommerce Attack Surface
REST API Routes 8
WordPress Hooks 16
Maintenance & Trust
Web3 Crypto Payments by DePay for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Web3 Crypto Payments by DePay for WooCommerce Alternatives
Web3 Crypto Payments by DePay for WordPress
depay-payments
Accept Web3 Crypto Payments & Donations. Supports various tokens, blockchains and wallets. MetaMask, Phantom, USDC, USDT, ETH, SOL, BSC, POL, xDAI…
Layer Crypto Checkout – Crypto Payments for WooCommerce
layer-crypto-checkout
Accept ETH and USDC payments via MetaMask or WalletConnect on Layer 2 networks (Base, Optimism, Arbitrum) with low fees.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Helio Pay (Accept 1-click crypto payments #USDC #SOL #BTC #ETH)
helio
Helio Pay ⚡⚡ Sell more with crypto ⚡⚡ - Accept crypto payments the easy way - Set up in minutes & get paid instantly with real-time payouts - Sell …
CryptAPI Payment Gateway for WooCommerce
cryptapi-payment-gateway-for-woocommerce
Accept cryptocurrency payments on your WooCommerce website
Web3 Crypto Payments by DePay for WooCommerce Developer Profile
2 plugins · 1K total installs
How We Detect Web3 Crypto Payments by DePay for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/depay-payments-for-woocommerce/assets/css/admin.css/wp-content/plugins/depay-payments-for-woocommerce/dist/ethers-5.7.umd.min.js/wp-content/plugins/depay-payments-for-woocommerce/dist/solana-web3.js/wp-content/plugins/depay-payments-for-woocommerce/dist/web3-blockchains.js/wp-content/plugins/depay-payments-for-woocommerce/dist/web3-client.js/wp-content/plugins/depay-payments-for-woocommerce/dist/widgets.bundle.js/wp-content/plugins/depay-payments-for-woocommerce/dist/react-token-image.js/wp-content/plugins/depay-payments-for-woocommerce/dist/admin.js/wp-content/plugins/depay-payments-for-woocommerce/dist/ethers-5.7.umd.min.js/wp-content/plugins/depay-payments-for-woocommerce/dist/solana-web3.js/wp-content/plugins/depay-payments-for-woocommerce/dist/web3-blockchains.js/wp-content/plugins/depay-payments-for-woocommerce/dist/web3-client.js/wp-content/plugins/depay-payments-for-woocommerce/dist/widgets.bundle.js/wp-content/plugins/depay-payments-for-woocommerce/dist/react-token-image.js+1 moredepay-payments-for-woocommerce/assets/css/admin.css?ver=depay-payments-for-woocommerce/dist/ethers-5.7.umd.min.js?ver=depay-payments-for-woocommerce/dist/solana-web3.js?ver=depay-payments-for-woocommerce/dist/web3-blockchains.js?ver=depay-payments-for-woocommerce/dist/web3-client.js?ver=depay-payments-for-woocommerce/dist/widgets.bundle.js?ver=depay-payments-for-woocommerce/dist/react-token-image.js?ver=depay-payments-for-woocommerce/dist/admin.js?ver=HTML / DOM Fingerprints
depay-wc-admin-wrapDEPAY_WC_ETHERSDEPAY_WC_SOLANA_WEB3DEPAY_WC_BLOCKCHAINSDEPAY_WC_CLIENTDEPAY_WC_WIDGETSDEPAY_WC_ADMIN+1 more