GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Security & Risk Analysis

wordpress.org/plugins/gourl-wpmudev-marketpress-bitcoin-payment-gateway-addon

Provides Bitcoin/Altcoin Payment Gateway for Wpmudev MarketPress 2.9+ or higher. Accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Dash, etc Payments …

10 active installs v1.1.2 PHP + WP 3.5+ Updated Jul 13, 2021
bitcoinbitcoin-cashbitcoincashbitcoinsmarketpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Safe to Use in 2026?

Generally Safe

Score 85/100

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of "gourl-wpmudev-marketpress-bitcoin-payment-gateway-addon" v1.1.2 reveals a generally strong security posture. The plugin exhibits no identified dangerous functions, SQL queries are exclusively prepared, and there are no file operations or external HTTP requests. Furthermore, the absence of shortcodes, cron events, and AJAX/REST API endpoints significantly limits the attack surface. The taint analysis also shows no identified unsanitized flows, indicating a low risk of common injection vulnerabilities.

Despite these strengths, there are a few areas for improvement. The low number of output escaping checks (50% proper escaping) suggests a potential risk for reflected cross-site scripting (XSS) vulnerabilities if not all outputs are adequately sanitized. The complete lack of nonce and capability checks on entry points, while currently not an issue due to the zero attack surface, could become a significant risk if future updates introduce new endpoints without proper authorization and validation.

The plugin's vulnerability history is also exceptionally clean, with no recorded CVEs. This, combined with the positive static analysis results, suggests a well-maintained and secure codebase. However, the lack of checks for nonces and capabilities remains a latent concern. While the current attack surface is zero, any introduction of new functionality could expose the site to vulnerabilities if these essential security measures are not implemented.

Key Concerns

  • Half of output checks are not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterplugin_action_linksgourl-marketpress.php:32
filtermp_order_status_section_title_payment_infogourl-marketpress.php:155
actionplugins_loadedgourl-marketpress.php:621
Maintenance & Trust

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 13, 2021
PHP min version
Downloads101K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon Developer Profile

gourl

11 plugins · 2K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
1910 days
View full developer profile
Detection Fingerprints

How We Detect GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
gourl_mp_admin_settings
HTML Comments
<!-- 1. --><!-- 2. --><!-- 2.1 -->
Data Attributes
data-gourl-langdata-gourl-coindata-gourl-amountdata-gourl-orderiddata-gourl-boxiddata-gourl-return+1 more
JS Globals
gourl_marketpress_settingsgourl_marketpress_settings.data
Shortcode Output
[gourl]
FAQ

Frequently Asked Questions about GoUrl MarketPress – Bitcoin Altcoin Payment Gateway Addon