EukaPay Cryptocurrency Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/eukapay-cryptocurrency-payment-gateway-for-woocommerce

Accept cryptocurrencies for payments on your store using EukaPay.

0 active installs v1.0.0 PHP 7.4+ WP 6.0.2+ Updated Oct 26, 2022
bitcoincryptocurrencyethereumusdcusdt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EukaPay Cryptocurrency Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

EukaPay Cryptocurrency Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The eukapay-cryptocurrency-payment-gateway-for-woocommerce plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of direct SQL queries without prepared statements, no file operations, and a high percentage of properly escaped output are commendable practices. Furthermore, the lack of known vulnerabilities in its history suggests a well-maintained codebase or a lack of public disclosure, both of which are positive indicators. The plugin also avoids common attack vectors such as direct AJAX handlers, REST API routes, or shortcodes without proper checks. This demonstrates a conscious effort to minimize the attack surface and adhere to secure coding principles.

However, there are a few areas that warrant attention. The presence of two external HTTP requests could potentially introduce risks if not handled with utmost care, especially if they interact with untrusted third-party services or handle sensitive data without encryption. More critically, the taint analysis indicates two flows with unsanitized paths. While classified as not critical or high severity in this specific analysis, unsanitized input is a fundamental security risk that can lead to various vulnerabilities like Cross-Site Scripting (XSS) or even SQL injection if not properly validated and escaped at the point of use. The complete lack of nonce checks and capability checks across all entry points is a significant concern. This means that any data processed through these entry points, even if indirectly, could be manipulated by unauthorized users, especially if the plugin were to evolve and expose more functionality.

In conclusion, while the plugin shows promising signs of secure development in many areas, the identified taint flows and the complete absence of nonce and capability checks represent notable weaknesses. These should be prioritized for remediation to ensure a robust security profile. The strong foundation in other areas provides a good base for addressing these specific concerns.

Key Concerns

  • Taint flows with unsanitized paths
  • External HTTP requests
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

EukaPay Cryptocurrency Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EukaPay Cryptocurrency Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

92% escaped13 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
payment_callback (includes\class-wc-gateway-eukapay.php:177)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EukaPay Cryptocurrency Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesincludes\class-wc-gateway-eukapay.php:48
actionwoocommerce_update_options_payment_gateways_includes\class-wc-gateway-eukapay.php:50
actionwoocommerce_api_wc_gateway_eukapayincludes\class-wc-gateway-eukapay.php:51
actionplugins_loadedwoocommerce-gateway-eukapay.php:21
filterwoocommerce_payment_gatewayswoocommerce-gateway-eukapay.php:22
Maintenance & Trust

EukaPay Cryptocurrency Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 26, 2022
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EukaPay Cryptocurrency Payment Gateway for WooCommerce Developer Profile

Tomo

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EukaPay Cryptocurrency Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eukapay-cryptocurrency-payment-gateway-for-woocommerce/assets/EukaPayEmailIcon.png

HTML / DOM Fingerprints

REST Endpoints
/wc-api/wc_gateway_eukapay
FAQ

Frequently Asked Questions about EukaPay Cryptocurrency Payment Gateway for WooCommerce