Heleket – Crypto Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/heleket-crypto-gateway-for-woocommerce

Important

60 active installs v1.3.5 PHP 7.4+ WP 6.3+ Updated Sep 16, 2025
accept-cryptobitcoin-payment-gatewaybitcoin-paymentscrypto-paymentspayment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Heleket – Crypto Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Heleket – Crypto Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The plugin "heleket-crypto-gateway-for-woocommerce" version 1.3.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices such as using prepared statements for all SQL queries and having a strong output escaping rate of 81%. It also correctly implements nonce checks and avoids dangerous functions. However, the presence of one unprotected REST API route is a significant concern, as it represents a direct entry point into the application that lacks proper authorization. The lack of taint analysis flows reported is generally positive, suggesting no immediately obvious critical or high severity vulnerabilities within the analyzed code paths.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical taint flows and the secure handling of SQL, suggests that the core functionality may be well-developed from a security perspective. Nonetheless, the unprotected REST API route is a tangible risk that could be exploited if it exposes sensitive functionality or data. The overall security is moderate, with a critical weakness in the exposed REST API that needs immediate attention despite a generally sound codebase.

Key Concerns

  • Unprotected REST API route
  • Low capability checks on entry points
Vulnerabilities
None known

Heleket – Crypto Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Heleket – Crypto Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
101 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

81% escaped125 total outputs
Attack Surface
1 unprotected

Heleket – Crypto Gateway for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/heleket-pay/check-statusheleket-crypto-gateway-for-woocommerce.php:252
WordPress Hooks 13
actionbefore_woocommerce_initheleket-crypto-gateway-for-woocommerce.php:44
filterwoocommerce_payment_gatewaysheleket-crypto-gateway-for-woocommerce.php:52
actionplugins_loadedheleket-crypto-gateway-for-woocommerce.php:64
filterwc_order_statusesheleket-crypto-gateway-for-woocommerce.php:69
actioninitheleket-crypto-gateway-for-woocommerce.php:82
filtertemplate_includeheleket-crypto-gateway-for-woocommerce.php:151
filterquery_varsheleket-crypto-gateway-for-woocommerce.php:160
actionrest_api_initheleket-crypto-gateway-for-woocommerce.php:248
actionrest_api_initheleket-crypto-gateway-for-woocommerce.php:259
actionadmin_enqueue_scriptsheleket-crypto-gateway-for-woocommerce.php:307
actionbefore_woocommerce_initheleket-crypto-gateway-for-woocommerce.php:335
actionwoocommerce_blocks_loadedheleket-crypto-gateway-for-woocommerce.php:338
actionwoocommerce_blocks_payment_method_type_registrationheleket-crypto-gateway-for-woocommerce.php:347
Maintenance & Trust

Heleket – Crypto Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version7.4
Downloads368

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Heleket – Crypto Gateway for WooCommerce Developer Profile

heleket

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Heleket – Crypto Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Heleket – Crypto Gateway for WooCommerce