Payment4 Crypto Payment gateway Security & Risk Analysis

wordpress.org/plugins/payment4-crypto-payment-gateway

Accept secure cryptocurrency payments in WooCommerce, Restrict Content Pro, Easy Digital Downloads, and Gravity Forms with Payment4.

20 active installs v3.0.1 PHP 7.0+ WP 6.0+ Updated Dec 20, 2025
cryptocurrencyeddgravity-formspayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Payment4 Crypto Payment gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Payment4 Crypto Payment gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the "payment4-crypto-payment-gateway" v3.0.1 plugin exhibits a generally strong security posture. The absence of identified critical or high-severity taint flows, along with the prevalent use of prepared statements for SQL queries and proper output escaping (95%), indicates good coding practices in these sensitive areas. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development.

However, there are a few areas that warrant attention. The plugin performs a file operation and makes a significant number of external HTTP requests, which can introduce potential risks if not handled securely. Crucially, the static analysis reveals zero nonce checks and only one capability check across all identified entry points, despite the presence of these entry points. This lack of robust authorization and integrity checks on all potential interaction points presents a significant concern for unauthorized access and manipulation.

In conclusion, while the plugin demonstrates strengths in core areas like database interaction and output sanitization, the absence of comprehensive nonce and capability checks on its entry points is a notable weakness. The potential risks associated with file operations and external HTTP requests, though not explicitly flagged as vulnerabilities, should also be monitored. The clean vulnerability history is positive, but the identified gaps in authorization checks could expose the plugin to attacks if these entry points are exploited.

Key Concerns

  • No nonce checks on entry points
  • Only 1 capability check on entry points
  • File operation present
  • 15 external HTTP requests
Vulnerabilities
None known

Payment4 Crypto Payment gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment4 Crypto Payment gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
54 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
15
Bundled Libraries
0

Output Escaping

95% escaped57 total outputs
Attack Surface

Payment4 Crypto Payment gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 51
actionplugins_loadedincludes\class-gateway-pro-loader.php:15
actiongform_loadedincludes\class-gateway-pro-loader.php:34
actionadmin_menuincludes\class-gateway-pro-loader.php:44
actionadmin_enqueue_scriptsincludes\class-gateway-pro-loader.php:45
actionadmin_initincludes\class-gateway-pro-loader.php:48
actionadmin_noticesincludes\class-gateway-pro-loader.php:49
actionadmin_initpayment4-crypto-payment-gateway.php:37
filteredd_payment_gatewaysplugins\edd\edd-pg.php:28
actionedd_payment4cpg_edd_cc_formplugins\edd\edd-pg.php:29
actionedd_gateway_payment4cpg_eddplugins\edd\edd-pg.php:30
actionedd_pre_process_purchaseplugins\edd\edd-pg.php:31
actioninitplugins\edd\edd-pg.php:32
actionpayment4cpg_edd_redirect_verifyplugins\edd\edd-pg.php:33
filteredd_currenciesplugins\edd\edd-pg.php:34
filteredd_accepted_payment_iconsplugins\edd\edd-pg.php:35
filteredd_currency_symbolplugins\edd\edd-pg.php:36
filteredd_payment_statusesplugins\edd\edd-pg.php:527
filterthe_contentplugins\edd\edd-pg.php:531
actionadmin_enqueue_scriptsplugins\edd\edd-pg.php:547
actionparse_requestplugins\gf\p4-class.php:78
actiongform_pre_handle_confirmationplugins\gf\p4-class.php:87
filtergform_currenciesplugins\gf\p4-class.php:88
filtergform_validation_messageplugins\gf\p4-class.php:89
actiongform_post_payment_actionplugins\gf\p4-class.php:90
filtergform_entry_list_columnsplugins\gf\p4-class.php:92
filtergform_entries_column_filterplugins\gf\p4-class.php:97
actiongform_loadedplugins\gf\p4-gf.php:9
filterthe_contentplugins\gf\p4-gf.php:37
actionrcp_payment_gatewaysplugins\rcp\rcp-pg.php:9
actionrcp_update_payment_status_completeplugins\rcp\rcp-pg.php:236
actionrcp_update_payment_status_failedplugins\rcp\rcp-pg.php:321
actioninitplugins\rcp\rcp-pg.php:570
filterrcp_currenciesplugins\rcp\rcp-pg.php:580
filterrcp_irr_currency_filter_beforeplugins\rcp\rcp-pg.php:592
filterrcp_irr_currency_filter_afterplugins\rcp\rcp-pg.php:593
filterrcp_irt_currency_filter_beforeplugins\rcp\rcp-pg.php:594
filterrcp_irt_currency_filter_afterplugins\rcp\rcp-pg.php:595
filterthe_contentplugins\rcp\rcp-pg.php:617
actionwp_enqueue_scriptsplugins\woo\class-wc-gateway-payment4.php:64
actionwoocommerce_cart_calculate_feesplugins\woo\class-wc-gateway-payment4.php:65
actionwoocommerce_checkout_update_order_reviewplugins\woo\class-wc-gateway-payment4.php:66
actionwoocommerce_update_options_payment_gatewaysplugins\woo\class-wc-gateway-payment4.php:81
filterwoocommerce_thankyou_order_received_textplugins\woo\class-wc-gateway-payment4.php:95
actionwoocommerce_before_thankyouplugins\woo\class-wc-gateway-payment4.php:96
filterwoocommerce_payment_gatewaysplugins\woo\index.php:26
actionbefore_woocommerce_initplugins\woo\index.php:29
actionwoocommerce_blocks_loadedplugins\woo\index.php:32
actionwoocommerce_blocks_payment_method_type_registrationplugins\woo\index.php:67
actioninitplugins\woo\index.php:138
filterwc_order_statusesplugins\woo\index.php:169
actionadmin_enqueue_scriptsplugins\woo\index.php:179
Maintenance & Trust

Payment4 Crypto Payment gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 20, 2025
PHP min version7.0
Downloads146

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Payment4 Crypto Payment gateway Developer Profile

Payment4

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment4 Crypto Payment gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment4-crypto-payment-gateway/assets/css/payment4.css
Version Parameters
payment4-crypto-payment-gateway/assets/css/payment4.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
payment4-crypto-payment-gatewaypayment4_gateway_pro_plugins
FAQ

Frequently Asked Questions about Payment4 Crypto Payment gateway