GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Security & Risk Analysis

wordpress.org/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon

Provides Bitcoin/Altcoin Payment Gateway for WooCommerce 2.1+ or higher. White Label Product. Accept Bitcoin, Bitcoin Cash, Bitcoin SV, Litecoin, Dash …

700 active installs v1.3.9 PHP + WP 3.5+ Updated Oct 27, 2023
accept-bitcoinbitcoinbitcoin-paymentsbitcoin-woocommercewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Safe to Use in 2026?

Generally Safe

Score 85/100

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon" v1.3.9 exhibits a generally good security posture in terms of its attack surface and known vulnerability history. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct public entry points to the plugin's functionality. Furthermore, the absence of any recorded CVEs indicates a history of responsible development or no significant past security issues being publicly disclosed.

However, there are specific areas of concern within the code analysis. The presence of a SQL query that does not utilize prepared statements is a significant risk, potentially opening the door to SQL injection vulnerabilities if user input is not meticulously sanitized before being passed to the query. Additionally, only 33% of output is properly escaped, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities where unsanitized data might be rendered in the browser. The taint analysis, while not revealing critical or high severity flows, did identify one flow with an unsanitized path, which, when combined with the poor output escaping and raw SQL, could exacerbate potential vulnerabilities.

In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the identified code-level weaknesses in SQL query preparation and output escaping are notable risks that require attention. These issues, if exploited, could lead to data breaches or unauthorized code execution.

Key Concerns

  • SQL query not using prepared statements
  • Low percentage of properly escaped output
  • Taint flow with unsanitized path
Vulnerabilities
None known

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
22
11 escaped
Nonce Checks
0
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

33% escaped33 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
cryptocoin_payment (gourl-woocommerce.php:1429)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 36
actionplugins_loadedgourl-woocommerce.php:31
filterplugin_action_linksgourl-woocommerce.php:32
actionplugins_loadedgourl-woocommerce.php:33
filterplugin_row_metagourl-woocommerce.php:34
filterwoocommerce_payment_gatewaysgourl-woocommerce.php:112
actionwoocommerce_view_ordergourl-woocommerce.php:113
actionwoocommerce_email_after_order_tablegourl-woocommerce.php:114
filterwoocommerce_currenciesgourl-woocommerce.php:115
filterwoocommerce_currency_symbolgourl-woocommerce.php:116
filterwc_get_price_decimalsgourl-woocommerce.php:117
filterwoocommerce_get_price_htmlgourl-woocommerce.php:118
actionwoocommerce_before_calculate_totalsgourl-woocommerce.php:121
actionwoocommerce_cart_calculate_feesgourl-woocommerce.php:124
actionwp_footergourl-woocommerce.php:126
filterwcs_view_subscription_actionsgourl-woocommerce.php:129
filterwoocommerce_get_sale_pricegourl-woocommerce.php:137
filterwoocommerce_get_regular_pricegourl-woocommerce.php:138
filterwoocommerce_get_pricegourl-woocommerce.php:139
filterwoocommerce_product_get_sale_pricegourl-woocommerce.php:143
filterwoocommerce_product_get_regular_pricegourl-woocommerce.php:144
filterwoocommerce_product_get_pricegourl-woocommerce.php:145
filterwoocommerce_product_variation_get_sale_pricegourl-woocommerce.php:147
filterwoocommerce_product_variation_get_regular_pricegourl-woocommerce.php:148
filterwoocommerce_product_variation_get_pricegourl-woocommerce.php:149
filterwoocommerce_variation_prices_sale_pricegourl-woocommerce.php:151
filterwoocommerce_variation_prices_regular_pricegourl-woocommerce.php:152
filterwoocommerce_variation_prices_pricegourl-woocommerce.php:153
filterwoocommerce_get_variation_prices_hashgourl-woocommerce.php:157
actionwoocommerce_before_calculate_totalsgourl-woocommerce.php:158
actionwoocommerce_admin_order_data_after_billing_addressgourl-woocommerce.php:159
filterwoocommerce_get_settings_productsgourl-woocommerce.php:160
actionwoocommerce_proceed_to_checkoutgourl-woocommerce.php:285
filterwoocommerce_available_payment_gatewaysgourl-woocommerce.php:346
actionwoocommerce_thankyou_gourlpaymentsgourl-woocommerce.php:1052
actionwoocommerce_subscription_unable_to_update_statusgourl-woocommerce.php:1057
actionadmin_footer_textgourl-woocommerce.php:1061
Maintenance & Trust

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 27, 2023
PHP min version
Downloads213K

Community Trust

Rating76/100
Number of ratings38
Active installs700
Developer Profile

GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon Developer Profile

gourl

11 plugins · 2K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
1910 days
View full developer profile
Detection Fingerprints

How We Detect GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon/assets/css/gourl.css/wp-content/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon/assets/js/gourl.js
Script Paths
/wp-content/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon/assets/js/gourl.js
Version Parameters
/wp-content/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon/assets/css/gourl.css?ver=/wp-content/plugins/gourl-woocommerce-bitcoin-altcoin-payment-gateway-addon/assets/js/gourl.js?ver=

HTML / DOM Fingerprints

CSS Classes
gourl-pay-button
HTML Comments
<!-- GoUrl.io Bitcoin Payment Gateway --><!-- GOURL: WooCommerce Gateway Settings --><!-- GOURL: Plugin Settings --><!-- GoUrl WooCommerce Bitcoin Payment -->+1 more
Data Attributes
data-gourl-buttondata-gourl-pricedata-gourl-product-iddata-gourl-currencydata-gourl-address
JS Globals
gourl_wc_params
Shortcode Output
[gourl_payment_widget][gourl_buy_button]
FAQ

Frequently Asked Questions about GoUrl WooCommerce – Bitcoin Altcoin Payment Gateway Addon