
Payid19 Crypto Payment Gateway Security & Risk Analysis
wordpress.org/plugins/payid19-com-payment-gateway-Crypto Payment Gateway you can accept USDT, Bitcoin, Litecoin, Ethereum, Bnb and TRX stable coins and withdraw as USDT.
Is Payid19 Crypto Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100Payid19 Crypto Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "payid19-com-payment-gateway" v2.0.0 exhibits several significant security concerns, primarily stemming from its unprotected entry points. While the code analysis shows good practices like 100% prepared statements for SQL queries and a high percentage of properly escaped output, the absence of authentication checks on both AJAX handlers is a critical oversight. This exposes the plugin to potential unauthorized actions if these handlers can be triggered by unauthenticated users. The lack of capability checks further exacerbates this risk, meaning that even if an attacker cannot directly trigger the AJAX actions, a lower-privileged user within WordPress could potentially do so.
Despite the static analysis not revealing any direct taint flows or dangerous functions, the two unprotected AJAX handlers represent a substantial attack surface. The absence of nonce checks on these handlers is also concerning, as it opens the door for Cross-Site Request Forgery (CSRF) attacks. The vulnerability history being clear of any past CVEs is a positive sign, suggesting a generally stable code base or a lack of targeted attacks. However, this should not overshadow the immediate risks identified in the current code analysis.
In conclusion, while the plugin demonstrates strengths in SQL handling and output escaping, the critical security flaws in its entry point protection (AJAX handlers without auth and capability checks) present a significant risk. The unprotected nature of these entry points, coupled with the lack of nonce verification, creates vulnerabilities that could be exploited by attackers. Prioritizing the implementation of robust authentication and authorization mechanisms for these handlers is paramount.
Key Concerns
- 2 unprotected AJAX handlers
- 0 Nonce checks on AJAX
- 0 Capability checks
Payid19 Crypto Payment Gateway Security Vulnerabilities
Payid19 Crypto Payment Gateway Release Timeline
Payid19 Crypto Payment Gateway Code Analysis
Output Escaping
Payid19 Crypto Payment Gateway Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Payid19 Crypto Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Payid19 Crypto Payment Gateway Alternatives
CryptoCloud – Crypto Payment Gateway
cryptocloud-crypto-payment-gateway
CryptoCloud - cryptocurrency payment system for business. We offer to you a possibility to accept payments worldwide in 40 cryptocurrencies.
OxaPay Crypto Payment Gateway: Accept Bitcoin Payments
oxapay
Secure crypto payment plugin for WordPress
OxaPay Crypto Payment Gateway for Paid Memberships Pro
oxapay-crypto-gateway-for-paid-memberships-pro
Accept cryptocurrency payments in Paid Memberships Pro using a secure and reliable gateway.
OxaPay Crypto Payment Gateway for Gravity Forms
oxapay-crypto-payment-gateway-for-gravity-forms
Accept cryptocurrency payments in Gravity Forms using a secure and reliable gateway.
OxaPay Crypto Payment Gateway For Restrict Content Pro
oxapay-crypto-payment-gateway-for-restrict-content-pro
Secure cryptocurrency payment gateway for Restrict Content Pro.
Payid19 Crypto Payment Gateway Developer Profile
1 plugin · 50 total installs
How We Detect Payid19 Crypto Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payid19-com-payment-gateway/admin/css/payid19-admin.css/wp-content/plugins/payid19-com-payment-gateway/admin/js/payid19-admin.js/wp-content/plugins/payid19-com-payment-gateway/public/css/payid19-public.css/wp-content/plugins/payid19-com-payment-gateway/public/js/payid19-public.js/wp-content/plugins/payid19-com-payment-gateway/admin/js/payid19-admin.js/wp-content/plugins/payid19-com-payment-gateway/public/js/payid19-public.jspayid19-admin.css?ver=payid19-admin.js?ver=payid19-public.css?ver=payid19-public.js?ver=HTML / DOM Fingerprints
payid19_ajax_object/wp-json/payid19/v1/order-status