Accept Cryptocurrencies with Plisio Security & Risk Analysis

wordpress.org/plugins/plisio-payment-gateway-for-woocommerce

The easiest and quickest way to accept Bitcoin, Litecoin, Ethereum and other cryptocurrencies.

1K active installs v2.0.6 PHP + WP 4.2+ Updated Feb 11, 2026
accept-bitcoinbitcoinethereumlitecoinplisio
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 15, 2026
Safety Verdict

Is Accept Cryptocurrencies with Plisio Safe to Use in 2026?

Mostly Safe

Score 78/100

Accept Cryptocurrencies with Plisio is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Apr 15, 2026Updated 3mo ago
Risk Assessment

The Plisio Payment Gateway for WooCommerce plugin v2.0.6 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs and the lack of dangerous functions or direct SQL queries are positive indicators. The plugin also demonstrates good practices by using prepared statements for its SQL queries and incorporating capability checks, albeit only one is noted. The limited attack surface with no unprotected entry points further enhances its security. However, there are notable weaknesses. The significantly low percentage of properly escaped output (25%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, which could allow attackers to inject malicious scripts into the website. The lack of nonce checks on entry points, while currently small in number, leaves potential room for Cross-Site Request Forgery (CSRF) attacks if new entry points are introduced or existing ones are misused. The single external HTTP request also warrants scrutiny to ensure it's handled securely and doesn't expose the site to risks from external services.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on entry points
  • Single external HTTP request
Vulnerabilities
1 published

Accept Cryptocurrencies with Plisio Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-6372medium · 5.3Missing Authorization

Accept Cryptocurrencies with Plisio <= 2.0.6 - Missing Authorization

Apr 15, 2026Unpatched
Version History

Accept Cryptocurrencies with Plisio Release Timeline

v2.0.6Current1 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.41 CVE
v1.0.31 CVE
Code Analysis
Analyzed Mar 16, 2026

Accept Cryptocurrencies with Plisio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

25% escaped8 total outputs
Attack Surface

Accept Cryptocurrencies with Plisio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwoocommerce_thankyou_plisioincludes\class-wc-gateway-plisio.php:66
actionwoocommerce_api_wc_gateway_plisioincludes\class-wc-gateway-plisio.php:67
actionwoocommerce_before_thankyouincludes\class-wc-gateway-plisio.php:69
filterdo_shortcode_tagincludes\class-wc-gateway-plisio.php:73
actionplugins_loadedwoocommerce-gateway-plisio.php:44
filterwoocommerce_payment_gatewayswoocommerce-gateway-plisio.php:49
actionwoocommerce_blocks_loadedwoocommerce-gateway-plisio.php:52
actionwoocommerce_blocks_payment_method_type_registrationwoocommerce-gateway-plisio.php:113
Maintenance & Trust

Accept Cryptocurrencies with Plisio Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedFeb 11, 2026
PHP min version
Downloads10K

Community Trust

Rating66/100
Number of ratings3
Active installs1K
Developer Profile

Accept Cryptocurrencies with Plisio Developer Profile

plisio

2 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Accept Cryptocurrencies with Plisio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/plisio.png/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-checkout.js/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/css/plisio-checkout.css/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-refund.js/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-gateway.js/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/css/plisio-gateway.css
Script Paths
/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-checkout.js/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-refund.js/wp-content/plugins/plisio-payment-gateway-for-woocommerce/assets/js/plisio-gateway.js
Version Parameters
plisio-payment-gateway-for-woocommerce/assets/js/plisio-checkout.js?ver=plisio-payment-gateway-for-woocommerce/assets/css/plisio-checkout.css?ver=plisio-payment-gateway-for-woocommerce/assets/js/plisio-refund.js?ver=plisio-payment-gateway-for-woocommerce/assets/js/plisio-gateway.js?ver=plisio-payment-gateway-for-woocommerce/assets/css/plisio-gateway.css?ver=

HTML / DOM Fingerprints

CSS Classes
plisio-gateway-form
HTML Comments
<!-- Begin Plisio Payment --><!-- End Plisio Payment --><!-- Plisio QR Code --><!-- Plisio Payment Link -->+2 more
Data Attributes
data-plisio-payment-urldata-plisio-payment-statusdata-plisio-checkout-urldata-plisio-order-id
JS Globals
PlisioCheckout
REST Endpoints
/wp-json/plisio/v1/payment-status
Shortcode Output
[plisio_payment_details][plisio_qr_code]
FAQ

Frequently Asked Questions about Accept Cryptocurrencies with Plisio