
Multi CryptoCurrency Payments Security & Risk Analysis
wordpress.org/plugins/multi-crypto-currency-paymentWooCommerce plugin - Multi CryptoCurrency Payments Requires at least WooCommerce: 6.0 Tested up to: 9.8.2 License: GPLv2 or later
Is Multi CryptoCurrency Payments Safe to Use in 2026?
Mostly Safe
Score 76/100Multi CryptoCurrency Payments is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin "multi-crypto-currency-payment" v2.0.7 exhibits a mixed security posture. On the positive side, the static analysis indicates a clean attack surface with no apparent unprotected entry points like AJAX handlers, REST API routes, or shortcodes. The use of prepared statements for all SQL queries is a significant strength, suggesting good practices in database interaction. However, the plugin's vulnerability history is a major concern. It has a known unpatched high-severity CVE related to SQL injection, which, despite the static analysis showing prepared statements, implies a potential gap or a vulnerability in a past version that may not have been fully remediated or is present in the current version in a way not detected by the static analysis. Furthermore, the relatively low percentage of properly escaped output (47%) suggests a risk of cross-site scripting (XSS) vulnerabilities, particularly if sensitive data is being displayed to users without adequate sanitization.
The static analysis did not reveal any critical or high-severity taint flows, which is reassuring. However, the presence of a capability check without any corresponding nonce checks or authorization for the few identified entry points could be a point of weakness if those entry points are indeed exploitable. The file operations, while not immediately flagged as dangerous, warrant careful inspection to ensure no sensitive files are being accessed or modified without proper authorization. The vulnerability history, specifically the unpatched SQL injection vulnerability, overrides the positive findings from the static analysis regarding SQL queries. It strongly suggests that a significant risk remains.
In conclusion, while the plugin demonstrates some good security practices, particularly in its SQL query handling and limited attack surface, the existence of an unpatched high-severity SQL injection vulnerability and a significant portion of unescaped output presents a considerable risk. Users should exercise caution, and developers should prioritize addressing the known CVE and improving output escaping to mitigate these risks.
Key Concerns
- Unpatched high severity CVE
- Low percentage of properly escaped output
- Vulnerability history of SQL Injection
Multi CryptoCurrency Payments Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Multi CryptoCurrency Payments <= 2.0.3 - Unauthenticated SQL Injection
Multi CryptoCurrency Payments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Multi CryptoCurrency Payments Attack Surface
WordPress Hooks 10
Maintenance & Trust
Multi CryptoCurrency Payments Maintenance & Trust
Maintenance Signals
Community Trust
Multi CryptoCurrency Payments Alternatives
ATLOS Crypto Payments for WooCommerce
atlos-payments
ATLOS is a permissionless non-custodial crypto payment gateway with recurring billing support. One-click signup. No KYC. No paperwork. No middleman.
Coinbase Commerce – Crypto Gateway for WooCommerce
commerce-coinbase-for-woocommerce
Coinbase Commerce is the best crypto gateway, allows users to checkout with popular crypto currencies such as Bitcoin, Bitcoin Cash, DAI, Ethereum, Do …
Accept Cryptocurrencies with Plisio
plisio-payment-gateway-for-woocommerce
The easiest and quickest way to accept Bitcoin, Litecoin, Ethereum and other cryptocurrencies.
CoinGate for WooCommerce
coingate-for-woocommerce
Accept Crypto Payments with CoinGate for WooCommerce
Speed Bitcoin and Stablecoin Payments for WooCommerce
speed-accept-bitcoin-payments
Start accepting bitcoin or stablecoin payments instantly on your platform using Speed, without exchange rate volatility risk.
Multi CryptoCurrency Payments Developer Profile
1 plugin · 300 total installs
How We Detect Multi CryptoCurrency Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multi-crypto-currency-payment/assets/mccp-admin.css/wp-content/plugins/multi-crypto-currency-payment/assets/mccp.css/wp-content/plugins/multi-crypto-currency-payment/vendor/apirone/apirone-sdk-php/src/assets/js/script.min.js