PayCoinPro Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/paycoinpro-for-woocommerce

Accept cryptocurrency payments on your WooCommerce store. Let customers pay with Bitcoin, Ethereum, Litecoin, USDT, and 50+ other cryptocurrencies via …

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Feb 24, 2026
bitcoincryptocurrencyethereumpayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PayCoinPro Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

PayCoinPro Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'paycoinpro-for-woocommerce' v1.0.0 exhibits a concerning security posture primarily due to a significant lack of authorization checks on its entry points. While the plugin demonstrates good practices in avoiding dangerous functions, raw SQL queries, and mostly proper output escaping, the presence of one unprotected REST API route creates a direct avenue for potential unauthorized access or manipulation.

The static analysis reveals a single REST API route that lacks permission callbacks, making it a critical vulnerability. This means any unauthenticated user could potentially interact with this endpoint, leading to unforeseen consequences depending on the functionality it exposes. The absence of nonce checks and capability checks on other potential entry points (though none were identified beyond the REST API) further exacerbates this issue.

With no recorded vulnerability history, it might seem like the plugin is secure. However, this lack of history, coupled with the identified security flaws, could indicate that vulnerabilities simply haven't been discovered or exploited yet, rather than an inherent security. The plugin has a small attack surface in terms of entry points, but the unprotected nature of the one identified is a significant weakness. Overall, the plugin has strengths in its handling of SQL and output, but the critical oversight in securing its REST API route poses a substantial risk.

Key Concerns

  • REST API route without permission callbacks
  • Lack of capability checks on entry points
  • Lack of nonce checks on entry points
Vulnerabilities
None known

PayCoinPro Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PayCoinPro Payment Gateway for WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

PayCoinPro Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped22 total outputs
Attack Surface
1 unprotected

PayCoinPro Payment Gateway for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/paycoinpro/v1/webhookpaycoinpro-gateway.php:100
WordPress Hooks 6
actionwoocommerce_email_before_order_tableincludes/class-wc-gateway-paycoinpro.php:79
actionadmin_noticespaycoinpro-gateway.php:47
filterwoocommerce_payment_gatewayspaycoinpro-gateway.php:57
actionplugins_loadedpaycoinpro-gateway.php:59
actionrest_api_initpaycoinpro-gateway.php:110
actionbefore_woocommerce_initpaycoinpro-gateway.php:191
Maintenance & Trust

PayCoinPro Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version7.4
Downloads162

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PayCoinPro Payment Gateway for WooCommerce Developer Profile

paycoinpro

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayCoinPro Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paycoinpro-for-woocommerce/assets/css/paycoinpro.css/wp-content/plugins/paycoinpro-for-woocommerce/assets/js/paycoinpro-checkout.js
Script Paths
/wp-content/plugins/paycoinpro-for-woocommerce/assets/js/paycoinpro-checkout.js
Version Parameters
paycoinpro-for-woocommerce/assets/css/paycoinpro.css?ver=paycoinpro-for-woocommerce/assets/js/paycoinpro-checkout.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-paycoinpro-api-keydata-paycoinpro-api-url
JS Globals
paycoinpro_params
REST Endpoints
/wp-json/paycoinpro/v1/webhook
FAQ

Frequently Asked Questions about PayCoinPro Payment Gateway for WooCommerce