Cryptocurrency Payment Gateway WooCommerce – MaxelPay Security & Risk Analysis

wordpress.org/plugins/maxelpay

MaxelPay plugin enables WordPress WooCommerce stores to effortlessly accept cryptocurrency as a payment method.

20 active installs v1.0.0 PHP 7.4+ WP 6.5+ Updated Nov 14, 2024
accept-cryptocryptocrypto-payment-gatewaycrypto-paymentswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Gateway WooCommerce – MaxelPay Safe to Use in 2026?

Generally Safe

Score 92/100

Cryptocurrency Payment Gateway WooCommerce – MaxelPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the 'maxelpay' v1.0.0 plugin reveals a generally strong security posture with no identified critical or high-severity issues within its code. The absence of dangerous functions, raw SQL queries, file operations, and a notably low percentage of unsanitized taint flows are all positive indicators. Furthermore, the plugin demonstrates good practices by properly escaping the vast majority of its output and utilizing prepared statements for its database interactions.

However, there are a few areas that warrant attention. The presence of an external HTTP request without clear authentication or authorization mechanisms could potentially be a vector for certain types of attacks if not handled with extreme care. Additionally, the lack of nonce checks on any identified entry points, although the attack surface is currently zero, suggests a potential oversight if the plugin were to expand its functionality in the future and introduce AJAX or REST API endpoints. The vulnerability history is currently clear, which is excellent, but this doesn't negate the importance of proactive security measures for the existing code.

In conclusion, 'maxelpay' v1.0.0 appears to be a secure plugin in its current state, adhering to many best practices. The primary concern lies in the external HTTP request and the potential for future expansion without robust authorization checks on new entry points. The absence of any past vulnerabilities is a strong positive, but ongoing vigilance and proper implementation of authentication and authorization for any new features are crucial for maintaining this secure standing.

Key Concerns

  • External HTTP request without clear auth
  • No nonce checks on entry points
Vulnerabilities
None known

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
43 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

96% escaped45 total outputs
Attack Surface

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionrest_api_initincludes\class-maxelpay-woo-order-handling.php:49
actionwoocommerce_thankyouincludes\class-maxelpay-woo-order-handling.php:50
actionwoocommerce_order_status_cancelledincludes\class-maxelpay-woo-order-handling.php:51
actionplugins_loadedmaxelpay.php:74
filterwoocommerce_payment_gatewaysmaxelpay.php:75
actionadmin_enqueue_scriptsmaxelpay.php:76
actionwoocommerce_blocks_loadedmaxelpay.php:77
actionadmin_noticesmaxelpay.php:108
actionwoocommerce_blocks_payment_method_type_registrationmaxelpay.php:161
Maintenance & Trust

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 14, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Cryptocurrency Payment Gateway WooCommerce – MaxelPay Developer Profile

mndpsingh287

8 plugins · 4.1M total installs

64
trust score
Avg Security Score
79/100
Avg Patch Time
1115 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Gateway WooCommerce – MaxelPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maxelpay/assets/css/maxelpay-admin.css/wp-content/plugins/maxelpay/assets/js/maxelpay-admin-notice.js
Script Paths
/wp-content/plugins/maxelpay/assets/js/maxelpay-admin-notice.js
Version Parameters
maxelpay/assets/css/maxelpay-admin.css?ver=maxelpay/assets/js/maxelpay-admin-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
maxelpay_modalmaxelpay_modal-overlaymaxelpay_modal-togglemaxelpay_modal-wrappermaxelpay_modal-transitionmaxelpay_modal-headermaxelpay_modal-closemaxelpay_modal-heading+2 more
Data Attributes
id="maxelpay_custom_maxelpay_modal"
JS Globals
window.jQuery
REST Endpoints
/wp-json/maxelpay/wc-api/order_status
FAQ

Frequently Asked Questions about Cryptocurrency Payment Gateway WooCommerce – MaxelPay