Payment Gateway Coinify for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payment-gateway-coinify-for-woocommerce

A cryptocurrency payment gateway for WooCommerce that integrates with Coinify.

0 active installs v1.0.1 PHP 7.2+ WP 6.3+ Updated Dec 9, 2025
bitcoincoinifycryptocurrencypayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway Coinify for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway Coinify for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The payment-gateway-coinify-for-woocommerce plugin version 1.0.1 exhibits a mixed security posture. While it demonstrates good practices in several areas, including the complete absence of dangerous functions, 100% use of prepared statements for SQL queries, and 100% proper output escaping, there are significant concerns regarding its attack surface. Specifically, two AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can introduce risks if not properly secured and validated. The lack of any recorded historical vulnerabilities might suggest a history of responsible development or simply that the plugin has not been extensively targeted or analyzed in the past. However, this absence of history should not be a substitute for robust security measures.

The primary risk stems from the unprotected AJAX handlers. These could potentially be exploited by an attacker to trigger actions within the plugin without proper user authorization, leading to unintended consequences or data manipulation. While no critical or high-severity taint flows were identified, the presence of unprotected entry points remains a tangible security weakness. The plugin's strengths lie in its secure handling of database interactions and output, but these are overshadowed by the readily accessible, unauthenticated AJAX endpoints. A balanced conclusion is that the plugin has a solid foundation in secure coding practices for data handling but requires immediate attention to secure its entry points.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without auth checks
Vulnerabilities
None known

Payment Gateway Coinify for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Payment Gateway Coinify for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
63 escaped
Nonce Checks
3
Capability Checks
2
File Operations
3
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped63 total outputs
Attack Surface
2 unprotected

Payment Gateway Coinify for WooCommerce Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_pgcfw_send_support_requestcoinify-payments.php:64
authwp_ajax_pgcfw_generate_secretcoinify-payments.php:1396

REST API Routes 1

POST/wp-json/pgcfw/v1/webhookcoinify-payments.php:1004
WordPress Hooks 14
actionplugins_loadedcoinify-payments.php:36
filterwoocommerce_payment_gatewayscoinify-payments.php:37
actionadmin_enqueue_scriptscoinify-payments.php:39
actionwoocommerce_blocks_payment_method_type_registrationcoinify-payments.php:46
filterwoocommerce_admin_field_custom_buttoncoinify-payments.php:333
actiontemplate_redirectcoinify-payments.php:580
actiontemplate_redirectcoinify-payments.php:690
actionpgcfw_check_coinify_payment_intentcoinify-payments.php:869
filterwoocommerce_order_button_textcoinify-payments.php:986
actionrest_api_initcoinify-payments.php:1003
actioninitcoinify-payments.php:1375
actiontemplate_redirectcoinify-payments.php:1406
actionadmin_enqueue_scriptscoinify-payments.php:1431
actionwoocommerce_thankyoucoinify-payments.php:1468

Scheduled Events 1

pgcfw_check_coinify_payment_intent
Maintenance & Trust

Payment Gateway Coinify for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.2
Downloads278

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Payment Gateway Coinify for WooCommerce Developer Profile

Coinify

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway Coinify for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-coinify-for-woocommerce/assets/js/coinify-support.js
Version Parameters
payment-gateway-coinify-for-woocommerce/assets/js/coinify-support.js?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
pgcfwAjax
FAQ

Frequently Asked Questions about Payment Gateway Coinify for WooCommerce