
Heleket – Crypto Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/heleket-crypto-gateway-for-woocommerceImportant
Is Heleket – Crypto Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Heleket – Crypto Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "heleket-crypto-gateway-for-woocommerce" version 1.3.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices such as using prepared statements for all SQL queries and having a strong output escaping rate of 81%. It also correctly implements nonce checks and avoids dangerous functions. However, the presence of one unprotected REST API route is a significant concern, as it represents a direct entry point into the application that lacks proper authorization. The lack of taint analysis flows reported is generally positive, suggesting no immediately obvious critical or high severity vulnerabilities within the analyzed code paths.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical taint flows and the secure handling of SQL, suggests that the core functionality may be well-developed from a security perspective. Nonetheless, the unprotected REST API route is a tangible risk that could be exploited if it exposes sensitive functionality or data. The overall security is moderate, with a critical weakness in the exposed REST API that needs immediate attention despite a generally sound codebase.
Key Concerns
- Unprotected REST API route
- Low capability checks on entry points
Heleket – Crypto Gateway for WooCommerce Security Vulnerabilities
Heleket – Crypto Gateway for WooCommerce Code Analysis
Output Escaping
Heleket – Crypto Gateway for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 13
Maintenance & Trust
Heleket – Crypto Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Heleket – Crypto Gateway for WooCommerce Alternatives
OxaPay Crypto Payment Gateway: Accept Bitcoin Payments
oxapay
Secure crypto payment plugin for WordPress
OxaPay Crypto Payment Gateway for Paid Memberships Pro
oxapay-crypto-gateway-for-paid-memberships-pro
Accept cryptocurrency payments in Paid Memberships Pro using a secure and reliable gateway.
OxaPay Crypto Payment Gateway for Gravity Forms
oxapay-crypto-payment-gateway-for-gravity-forms
Accept cryptocurrency payments in Gravity Forms using a secure and reliable gateway.
OxaPay Crypto Payment Gateway For Restrict Content Pro
oxapay-crypto-payment-gateway-for-restrict-content-pro
Secure cryptocurrency payment gateway for Restrict Content Pro.
ATLOS Crypto Payments for WooCommerce
atlos-payments
ATLOS is a permissionless non-custodial crypto payment gateway with recurring billing support. One-click signup. No KYC. No paperwork. No middleman.
Heleket – Crypto Gateway for WooCommerce Developer Profile
1 plugin · 60 total installs
How We Detect Heleket – Crypto Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.