
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/paymento-crypto-gatewayAccept Bitcoin, Ethereum, and USDT in WooCommerce with Paymento – a secure, non-custodial crypto payment gateway.
Is Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "paymento-crypto-gateway" plugin version 1.2.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by ensuring all SQL queries utilize prepared statements and all output is properly escaped. It also avoids dangerous functions and file operations. However, significant security concerns arise from its attack surface and the lack of robust authorization checks.
The static analysis reveals a notable risk with 2 out of 3 REST API routes lacking permission callbacks. This means that unauthorized users could potentially interact with these endpoints, leading to unintended actions or information disclosure. While the taint analysis did not find critical or high-severity issues, the presence of one flow with an unsanitized path warrants attention, even if its immediate impact is unclear without further context.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests that historically, the plugin has not been a target for publicly disclosed vulnerabilities. However, the absence of vulnerabilities does not equate to perfect security, especially given the identified weaknesses in the attack surface. The lack of nonce checks is also a concern, particularly if any of the unprotected REST API routes are involved in state-changing operations.
Key Concerns
- 2 REST API routes without permission callbacks
- 1 flow with unsanitized paths
- 0 nonce checks on entry points
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Security Vulnerabilities
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Release Timeline
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Attack Surface
REST API Routes 3
WordPress Hooks 15
Maintenance & Trust
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Alternatives
Cryptocurrency Payment Gateway
cryptocurrency-payment-gateway
Digital Currency Payment Gateway for WooCommerce. Easily accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, and more in your store.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
OxaPay Crypto Payment Gateway: Accept Bitcoin Payments
oxapay
Secure crypto payment plugin for WordPress
xMoney Crypto for WooCommerce
utrust-for-woocommerce
Accept Bitcoin, Ethereum, xMoney Token and other cryptocurrencies directly on your online store and get settled in fiat for 1% fee.
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce Developer Profile
1 plugin · 50 total installs
How We Detect Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/paymento-crypto-gateway/assets/js/paymento-gateway.js/wp-content/plugins/paymento-crypto-gateway/assets/css/paymento-gateway.css/wp-content/plugins/paymento-crypto-gateway/assets/images/paymento-badge.png/wp-content/plugins/paymento-crypto-gateway/assets/js/paymento-gateway.jspaymento-crypto-gateway/assets/js/paymento-gateway.js?ver=paymento-crypto-gateway/assets/css/paymento-gateway.css?ver=HTML / DOM Fingerprints
paymento-gateway-wrapperpaymento-gateway-button<!-- Paymento Crypto Gateway --><!-- Paymento Blocks Support -->data-paymento-keydata-paymento-amountwindow.paymentoGatewayConfigvar paymentoGatewayvar PAYMENTOGW_URL/wp-json/paymento/v1/webhook[paymento_gateway_checkout]