GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Security & Risk Analysis

wordpress.org/plugins/gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon

Provides Bitcoin/Altcoin Payment Gateway for WP eCommerce 3.8.10+ or higher. Accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Dash, etc Payments on Y …

40 active installs v1.1.2 PHP + WP 3.5+ Updated Jul 13, 2021
bitcoinbitcoincashwp-e-commercewp-ecommercewpecommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Safe to Use in 2026?

Generally Safe

Score 85/100

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The security posture of the gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon v1.1.2 appears strong from a high-level perspective, with no publicly disclosed vulnerabilities and good practices evident in its SQL handling. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection. The absence of external HTTP requests and file operations also reduces the attack surface. However, the static analysis reveals a critical weakness in output escaping, with only 11% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data rendered to the user could be manipulated. The taint analysis also identified three flows with unsanitized paths, which, while not classified as critical or high severity, still indicate potential vulnerabilities. The lack of nonce and capability checks on entry points, combined with the low output escaping rate, presents a significant concern. The plugin's vulnerability history is clean, which is positive, but it doesn't negate the risks identified in the current code analysis. Overall, the plugin exhibits strong internal data handling but significant weaknesses in protecting against external data manipulation through unsanitized output.

Key Concerns

  • Low output escaping rate
  • Unsanitized paths in taint analysis
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
17
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

11% escaped19 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
display_order_notes (gourl-wp-ecommerce.php:518)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterplugin_action_linksgourl-wp-ecommerce.php:29
actionwpsc_transaction_result_cart_itemgourl-wp-ecommerce.php:30
actionwpsc_billing_details_bottomgourl-wp-ecommerce.php:31
Maintenance & Trust

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 13, 2021
PHP min version
Downloads103K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon Developer Profile

gourl

11 plugins · 2K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
1910 days
View full developer profile
Detection Fingerprints

How We Detect GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon/gourl.css/wp-content/plugins/gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon/gourl.js
Script Paths
/wp-content/plugins/gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon/gourl.js

HTML / DOM Fingerprints

Data Attributes
GOURLWPSC
JS Globals
GOURLWPSC
FAQ

Frequently Asked Questions about GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon