
Ether and ERC20 tokens WooCommerce Payment Gateway Security & Risk Analysis
wordpress.org/plugins/ether-and-erc20-tokens-woocommerce-payment-gatewayEther and ERC20 tokens WooCommerce Payment Gateway enables customers to pay with Ether or any ERC20, ERC777 or ERC223 tokens on your WooCommerce store …
Is Ether and ERC20 tokens WooCommerce Payment Gateway Safe to Use in 2026?
Generally Safe
Score 92/100Ether and ERC20 tokens WooCommerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ether-and-erc20-tokens-woocommerce-payment-gateway" plugin v4.18.1 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are significant positives, indicating a history of secure development or prompt patching. The plugin also excels in several good security practices, including 100% of SQL queries using prepared statements and a high percentage (89%) of properly escaped output. Furthermore, the plugin implements nonce checks and capability checks, and all identified entry points (AJAX, REST API, shortcodes, cron events) appear to have authentication mechanisms in place.
However, there are areas for concern. The taint analysis reveals two flows with unsanitized paths, which, despite being categorized as critical/high severity zero, still represent potential weaknesses that could be exploited if data originates from untrusted sources. The presence of file operations and external HTTP requests, while not inherently insecure, increases the plugin's attack surface and could be vectors for vulnerabilities if not handled with extreme care and proper input validation. The inclusion of bundled libraries like DataTables and Freemius, especially Freemius v1.0, raises a flag; outdated or vulnerable versions of bundled libraries are a common source of security issues, and their specific version here needs careful scrutiny.
In conclusion, the plugin has a commendable foundation in security best practices. The lack of known vulnerabilities is a strong indicator of its current security. Nevertheless, the two unsanitized taint flows and the potential risks associated with bundled libraries warrant attention. The plugin's overall security is good, but these specific points suggest areas where further hardening and validation are advisable to mitigate any latent risks.
Key Concerns
- Taint flows with unsanitized paths
- Bundled library Freemius v1.0 may be outdated
- Presence of file operations increases attack surface
- Presence of external HTTP requests increases attack surface
Ether and ERC20 tokens WooCommerce Payment Gateway Security Vulnerabilities
Ether and ERC20 tokens WooCommerce Payment Gateway Release Timeline
Ether and ERC20 tokens WooCommerce Payment Gateway Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Ether and ERC20 tokens WooCommerce Payment Gateway Attack Surface
WordPress Hooks 39
Maintenance & Trust
Ether and ERC20 tokens WooCommerce Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Ether and ERC20 tokens WooCommerce Payment Gateway Alternatives
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Coinley – Cryptocurrency Payments
coinley-payment-gateway
Accept cryptocurrency payments on your WooCommerce store with lower fees, instant settlements, and no chargebacks.
Layer Crypto Checkout – Crypto Payments for WooCommerce
layer-crypto-checkout
Accept ETH and USDC payments via MetaMask or WalletConnect on Layer 2 networks (Base, Optimism, Arbitrum) with low fees.
Nicky
nicky-me
Secure cryptocurrency payment gateway for WooCommerce. Accept Bitcoin, Ethereum, USDT and more.
PayCoinPro Payment Gateway for WooCommerce
paycoinpro-for-woocommerce
Accept cryptocurrency payments on your WooCommerce store. Let customers pay with Bitcoin, Ethereum, Litecoin, USDT, and 50+ other cryptocurrencies via …
Ether and ERC20 tokens WooCommerce Payment Gateway Developer Profile
7 plugins · 280 total installs
How We Detect Ether and ERC20 tokens WooCommerce Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ether-and-erc20-tokens-woocommerce-payment-gateway/ether-and-erc20-tokens-woocommerce-payment-gateway.phpHTML / DOM Fingerprints
ether_and_erc20_tokens_woocommerce_payment_gateway_freemius_init