Simple Bitcoin donations for WooCommerce Security & Risk Analysis

wordpress.org/plugins/simple-bitcoin-donations-for-woocommerce

This plugin lets you add Bitcoin donations to your WooCommerce checkout page.

0 active installs v1.1 PHP + WP 5.0+ Updated Sep 18, 2025
bitcoinbitcoin-donatebitcoin-donationsdonationswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Bitcoin donations for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Bitcoin donations for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The static analysis of the "simple-bitcoin-donations-for-woocommerce" plugin version 1.1 reveals a strong adherence to secure coding practices. The absence of any identified attack surface points, dangerous functions, raw SQL queries, or unsanitized taint flows is commendable. Furthermore, all identified output is properly escaped, indicating a low risk of cross-site scripting vulnerabilities. The plugin also refrains from file operations and external HTTP requests, minimizing potential attack vectors.

However, the complete lack of nonce checks and capability checks across all entry points, combined with zero AJAX handlers and REST API routes, presents a significant area of concern. While the current analysis found no active vulnerabilities, the absence of these fundamental security mechanisms means that if any entry points were to be introduced or exposed in future updates without proper authorization, they would be inherently vulnerable. The bundled Freemius and TCPDF libraries should also be monitored for potential outdated versions, although the static analysis does not indicate immediate issues with them.

Overall, the plugin demonstrates a solid foundation in secure coding for its current version. The vulnerability history being clear of any past issues is a positive sign. Nevertheless, the absence of critical security checks like nonces and capability checks on all entry points represents a potential weakness that could be exploited if the plugin's attack surface expands or if specific functions are not adequately secured in the future. Vigilance and robust security checks in future development are recommended.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
  • Bundled Freemius v1.0 library
  • Bundled TCPDF library
Vulnerabilities
None known

Simple Bitcoin donations for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Bitcoin donations for WooCommerce Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

Simple Bitcoin donations for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Freemius1.0TCPDF

Output Escaping

100% escaped20 total outputs
Attack Surface

Simple Bitcoin donations for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwoocommerce_settings_tabs_arraysimple-bitcoin-donations-for-woocommerce.php:58
actionwoocommerce_settings_tabs_btcdonations_tabsimple-bitcoin-donations-for-woocommerce.php:59
actionwoocommerce_update_options_btcdonations_tabsimple-bitcoin-donations-for-woocommerce.php:60
actionwoocommerce_admin_field_custom_typesimple-bitcoin-donations-for-woocommerce.php:62
Maintenance & Trust

Simple Bitcoin donations for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 18, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Simple Bitcoin donations for WooCommerce Developer Profile

theorcawp

11 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Bitcoin donations for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-bitcoin-donations-for-woocommerce/style.css/wp-content/plugins/simple-bitcoin-donations-for-woocommerce/js/simple-bitcoin-donations-for-woocommerce.js
Script Paths
/wp-content/plugins/simple-bitcoin-donations-for-woocommerce/js/simple-bitcoin-donations-for-woocommerce.js
Version Parameters
simple-bitcoin-donations-for-woocommerce/style.css?ver=simple-bitcoin-donations-for-woocommerce/js/simple-bitcoin-donations-for-woocommerce.js?ver=

HTML / DOM Fingerprints

Shortcode Output
<p style='border: 1px solid #e0dadf; padding: 20px; margin: 2em 0 2em 0; text-align: center; border-radius: 5px;'><img width="200" src="" alt="Bitcoin QR Code" style="display:block;margin:0 auto;" /><img src="
FAQ

Frequently Asked Questions about Simple Bitcoin donations for WooCommerce