Instant Crypto Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/instant-crypto-payments-for-woocommerce

Accept crypto payments (ICP, Bitcoin, stablecoins) in WooCommerce via ICPay. Gateway for secure checkout and webhook order updates.

0 active installs v1.3.8 PHP 7.4+ WP 6.0+ Updated Feb 8, 2026
bitcoincryptopaymentsusdcwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Instant Crypto Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Instant Crypto Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "instant-crypto-payments-for-woocommerce" plugin version 1.3.8 exhibits a generally positive security posture, with several good practices observed in its codebase. The absence of dangerous functions, file operations, and raw SQL queries, along with a high percentage of properly escaped output and the use of prepared statements, are strong indicators of secure development. The plugin also demonstrates a commitment to security by including nonce and capability checks where appropriate.

However, there are specific areas that warrant attention. The presence of two unprotected REST API routes represents a potential attack vector, as these endpoints lack proper permission callbacks, leaving them vulnerable to unauthorized access and manipulation. While taint analysis shows no critical or high-severity issues and the vulnerability history is clean, the unprotected entry points are a tangible risk that could be exploited if they handle sensitive data or perform critical actions without proper authentication or authorization.

Overall, the plugin's current state is good, with no known vulnerabilities. The primary concern stems from the identified unprotected REST API routes. Addressing these would further strengthen its security and mitigate potential risks. Continued vigilance in maintaining secure coding practices and promptly addressing any future vulnerabilities will be crucial.

Key Concerns

  • Unprotected REST API routes
  • Unprotected AJAX handlers
Vulnerabilities
None known

Instant Crypto Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Instant Crypto Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
25 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

96% escaped26 total outputs
Attack Surface
2 unprotected

Instant Crypto Payments for WooCommerce Attack Surface

Entry Points6
Unprotected2

AJAX Handlers 2

authwp_ajax_icpay_expressinstant-crypto-payments-for-woocommerce.php:82
noprivwp_ajax_icpay_expressinstant-crypto-payments-for-woocommerce.php:83

REST API Routes 4

POST/wp-json/instant-crypto-payments-for-woocommerce/v1/wc/webhookinstant-crypto-payments-for-woocommerce.php:98
POST/wp-json/instant-crypto-payments-for-woocommerce/v1/wc/confirm-paymentinstant-crypto-payments-for-woocommerce.php:103
POST/wp-json/instant-crypto-payments-for-woocommerce/v1/wc/expressinstant-crypto-payments-for-woocommerce.php:108
POST/wp-json/instant-crypto-payments-for-woocommerce/v1/wc/recheckinstant-crypto-payments-for-woocommerce.php:120
WordPress Hooks 13
actionplugins_loadedinstant-crypto-payments-for-woocommerce.php:48
actionbefore_woocommerce_initinstant-crypto-payments-for-woocommerce.php:55
actionwoocommerce_blocks_payment_method_type_registrationinstant-crypto-payments-for-woocommerce.php:63
filterwoocommerce_payment_gatewaysinstant-crypto-payments-for-woocommerce.php:77
actionrest_api_initinstant-crypto-payments-for-woocommerce.php:78
actionwp_enqueue_scriptsinstant-crypto-payments-for-woocommerce.php:79
actionenqueue_block_assetsinstant-crypto-payments-for-woocommerce.php:80
actionplugins_loadedinstant-crypto-payments-for-woocommerce.php:187
actionwoocommerce_checkout_order_processedinstant-crypto-payments-for-woocommerce.php:961
actionicpay_payments_for_wc_single_recheckinstant-crypto-payments-for-woocommerce.php:974
filtercron_schedulesinstant-crypto-payments-for-woocommerce.php:986
actioninitinstant-crypto-payments-for-woocommerce.php:993
actionicpay_payments_for_wc_recheck_pendinginstant-crypto-payments-for-woocommerce.php:999

Scheduled Events 5

icpay_payments_for_wc_single_recheck
icpay_payments_for_wc_single_recheck
icpay_payments_for_wc_single_recheck
icpay_payments_for_wc_recheck_pending
icpay_payments_for_wc_recheck_pending
Maintenance & Trust

Instant Crypto Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version7.4
Downloads291

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Instant Crypto Payments for WooCommerce Developer Profile

icpay

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Instant Crypto Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instant-crypto-payments-for-woocommerce/assets/js/icpay-embed.min.js
Script Paths
/wp-content/plugins/instant-crypto-payments-for-woocommerce/assets/js/icpay-embed.min.js
Version Parameters
/assets/js/icpay-embed.min.js?ver=1.3.8/assets/js/icpay-frontend-fixes.js?ver=1.3.8

HTML / DOM Fingerprints

CSS Classes
icpay-wc-qr-overlayicpay-modal-overlay
Data Attributes
data-pnp-rootdata-pnp-modal
JS Globals
ICPay_Payments_For_WC_Versionicpay_express_params
REST Endpoints
/instant-crypto-payments-for-woocommerce/v1/wc/webhook/instant-crypto-payments-for-woocommerce/v1/wc/confirm-payment/instant-crypto-payments-for-woocommerce/v1/wc/express/instant-crypto-payments-for-woocommerce/v1/wc/recheck
FAQ

Frequently Asked Questions about Instant Crypto Payments for WooCommerce