ForumPay Crypto Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/forumpay-crypto-payments

ForumPay Payment Gateway Module for Woocommerce

100 active installs v2.4.1 PHP 7.4+ WP 6.2+ Updated Mar 17, 2026
cryptocurrencygatewaypaymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ForumPay Crypto Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ForumPay Crypto Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'forumpay-crypto-payments' plugin version 2.3.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin demonstrates a commitment to secure coding practices by having no identified critical or high severity taint flows, zero known CVEs, and a low number of unprotected entry points. The use of prepared statements for all SQL queries and a high percentage of properly escaped output further strengthens its defenses. The presence of nonce checks and file operation handling, while present, are noted as areas where deeper inspection might be beneficial.

However, a significant concern is the complete absence of capability checks on any of its entry points. While the static analysis reports no unprotected REST API routes or AJAX handlers, the lack of explicit capability checks leaves a potential gap where unauthorized users might be able to interact with plugin functionalities if other implicit checks fail or are bypassed. The limited scope of the static analysis, particularly the zero taint flows analyzed, means that more complex or subtle vulnerabilities might remain undetected. The plugin's clean vulnerability history is a positive indicator of ongoing security awareness, but it does not guarantee future immunity.

Key Concerns

  • No capability checks on entry points
  • Limited taint flow analysis scope
  • Potential for unescaped output issues
Vulnerabilities
None known

ForumPay Crypto Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ForumPay Crypto Payments for WooCommerce Release Timeline

v2.4.1Current
v2.4.0
v2.3.1
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
Code Analysis
Analyzed Mar 16, 2026

ForumPay Crypto Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
45 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped49 total outputs
Attack Surface

ForumPay Crypto Payments for WooCommerce Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/wc-api/wc_forumpaysrc\ForumPayPaymentGateway.php:223
WordPress Hooks 13
actionplugins_loadedforumpay-crypto-payments.php:80
actionwoocommerce_update_options_payment_gatewayssrc\ForumPayPaymentGateway.php:144
actionwoocommerce_api_wc_forumpaysrc\ForumPayPaymentGateway.php:148
actionrest_api_initsrc\ForumPayPaymentGateway.php:149
filterwoocommerce_payment_gatewayssrc\ForumPayPaymentGateway.php:150
actionwoocommerce_admin_order_data_after_billing_addresssrc\ForumPayPaymentGateway.php:151
actionwp_enqueue_scriptssrc\ForumPayPaymentGateway.php:153
actionadmin_enqueue_scriptssrc\ForumPayPaymentGateway.php:155
actionadmin_enqueue_scriptssrc\ForumPayPaymentGateway.php:156
actionbefore_woocommerce_initsrc\ForumPayPaymentGateway.php:158
actionwoocommerce_initsrc\ForumPayPaymentGateway.php:160
actionadmin_noticessrc\ForumPayPaymentGateway.php:162
actionwoocommerce_blocks_payment_method_type_registrationsrc\ForumPayPaymentGateway.php:311
Maintenance & Trust

ForumPay Crypto Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 17, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

ForumPay Crypto Payments for WooCommerce Developer Profile

ForumPay

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ForumPay Crypto Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway.js/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway-admin.js/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway-order-edit.js
Script Paths
https://forumpay.com/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway.jshttps://forumpay.com/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway-admin.jshttps://forumpay.com/wp-content/plugins/forumpay-crypto-payments/assets/js/forumpay-payment-gateway-order-edit.js
Version Parameters
forumpay-crypto-payments/assets/js/forumpay-payment-gateway.js?ver=forumpay-crypto-payments/assets/js/forumpay-payment-gateway-admin.js?ver=forumpay-crypto-payments/assets/js/forumpay-payment-gateway-order-edit.js?ver=

HTML / DOM Fingerprints

CSS Classes
forumpay-payment-gateway
HTML Comments
Forumpay Payment Gateway.Provides a Crypto Payment Gateway.
Data Attributes
data-forumpay-pos-iddata-forumpay-siddata-forumpay-api-urldata-forumpay-api-userdata-forumpay-api-keydata-forumpay-webhook-url+7 more
JS Globals
forumpay_gateway_params
REST Endpoints
/wp-json/forumpay/v1/webhook/wp-json/forumpay/v1/success
Shortcode Output
[forumpay_payment_status]
FAQ

Frequently Asked Questions about ForumPay Crypto Payments for WooCommerce