Speed Bitcoin and Stablecoin Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/speed-accept-bitcoin-payments

Start accepting bitcoin or stablecoin payments instantly on your platform using Speed, without exchange rate volatility risk.

80 active installs v2.1.0 PHP 7.2+ WP 5.0+ Updated Oct 31, 2025
accept-bitcoinbitcoinbitcoin-paymentsbitcoin-woocommercecrypto-payment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Speed Bitcoin and Stablecoin Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Speed Bitcoin and Stablecoin Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "speed-accept-bitcoin-payments" plugin v2.1.0 presents a concerning security posture due to a significant number of unprotected entry points. The static analysis reveals three AJAX handlers, all of which lack authentication checks. This creates a substantial attack surface where malicious actors could potentially trigger arbitrary actions within the plugin without proper authorization. While the plugin demonstrates good practices in its handling of SQL queries, using prepared statements exclusively, and the absence of known vulnerabilities in its history, the lack of input sanitization for file operations and external HTTP requests, as indicated by the taint analysis, warrants attention. The plugin also exhibits weaknesses in output escaping, with a notable percentage of outputs not being properly sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these outputs. Despite the clean vulnerability history, the identified code signals and taint flows point to critical areas that require immediate remediation to ensure secure operation.

Key Concerns

  • 3 unprotected AJAX handlers
  • Taint analysis: 2 flows with unsanitized paths
  • Low output escaping (36% proper)
  • File operations without clear sanitization
  • External HTTP requests without clear sanitization
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
Vulnerabilities
None known

Speed Bitcoin and Stablecoin Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Speed Bitcoin and Stablecoin Payments for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Speed Bitcoin and Stablecoin Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

36% escaped39 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_plugin_options (includes\WooCommerce\Speed_Payment_Gateway.php:103)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Speed Bitcoin and Stablecoin Payments for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_handle_speed_store_secretspeed-accept-bitcoin-payments.php:64
authwp_ajax_speed_store_restrictedspeed-accept-bitcoin-payments.php:65
authwp_ajax_speed_disconnectspeed-accept-bitcoin-payments.php:66
WordPress Hooks 12
actionwp_enqueue_scriptsincludes\Assets.php:16
actionadmin_enqueue_scriptsincludes\Assets.php:17
actionwoocommerce_api_wc_gateway_speedincludes\WooCommerce\Speed_Payment_Gateway.php:68
actionplugins_loadedspeed-accept-bitcoin-payments.php:63
filterhttp_request_timeoutspeed-accept-bitcoin-payments.php:67
filterwoocommerce_payment_gatewaysspeed-accept-bitcoin-payments.php:109
actionadmin_noticesspeed-accept-bitcoin-payments.php:205
actionbefore_woocommerce_initspeed-accept-bitcoin-payments.php:250
actionwoocommerce_blocks_loadedspeed-accept-bitcoin-payments.php:257
actionwoocommerce_blocks_payment_method_type_registrationspeed-accept-bitcoin-payments.php:264
actioninitspeed-accept-bitcoin-payments.php:278
actiontemplate_redirectspeed-accept-bitcoin-payments.php:280
Maintenance & Trust

Speed Bitcoin and Stablecoin Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 31, 2025
PHP min version7.2
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs80
Developer Profile

Speed Bitcoin and Stablecoin Payments for WooCommerce Developer Profile

Speed

1 plugin · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Speed Bitcoin and Stablecoin Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/speed-accept-bitcoin-payments/assets/js/speed-payment-gateway.js/wp-content/plugins/speed-accept-bitcoin-payments/assets/css/speed-payment-gateway.css
Script Paths
/wp-content/plugins/speed-accept-bitcoin-payments/assets/js/speed-payment-gateway.js
Version Parameters
speed-accept-bitcoin-payments/assets/js/speed-payment-gateway.js?ver=speed-accept-bitcoin-payments/assets/css/speed-payment-gateway.css?ver=

HTML / DOM Fingerprints

CSS Classes
speed-bitcoin-payment-formspeed-payment-gateway-settings
HTML Comments
<!-- WC Speed Bitcoin Payment Gateway --><!-- Speed Bitcoin Payment for WooCommerce Settings -->
Data Attributes
data-speed-payment-modedata-speed-api-keydata-speed-webhook-secret
JS Globals
window.speedPaymentConfigvar speedPaymentAjaxUrl
REST Endpoints
/wp-json/speed-bitcoin-payment/v1/process-payment/wp-json/speed-bitcoin-payment/v1/webhook
Shortcode Output
[speed_bitcoin_payment_button][speed_bitcoin_invoice_details]
FAQ

Frequently Asked Questions about Speed Bitcoin and Stablecoin Payments for WooCommerce