Spreebie Barter – Ethereum Payments and Donations Security & Risk Analysis

wordpress.org/plugins/spreebie-barter

The SPREEBIE BARTER plugin is a widget that enables easy and fast Ethereum payments on any WordPress website via Metamask.

10 active installs v1.0.1 PHP + WP 4.1+ Updated Unknown
cryptodonationsethereummetamaskpayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spreebie Barter – Ethereum Payments and Donations Safe to Use in 2026?

Generally Safe

Score 100/100

Spreebie Barter – Ethereum Payments and Donations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "spreebie-barter" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are significant strengths. Furthermore, the presence of nonce checks (7) and capability checks (1) on its entry points, coupled with a high percentage of properly escaped output (84%), indicates good development practices. The lack of any reported vulnerabilities in its history, including critical or high severity ones, further bolsters this positive assessment.

However, there are minor areas for attention. While the attack surface is composed solely of AJAX handlers and all of them have authentication checks, the fact that there are 6 AJAX handlers could be a point of scrutiny if more detailed analysis revealed potential logic flaws within those handlers. The 84% output escaping, while good, means that 16% of outputs are not properly escaped, presenting a potential XSS vector, albeit likely low severity given the absence of other known issues. The absence of taint analysis results is noted; while this can mean no issues were found, it also means this area wasn't thoroughly explored in the provided data. Overall, the plugin appears to be well-developed with a focus on security, but the minor output escaping gap and the sheer number of AJAX handlers warrant a degree of cautiousness.

Key Concerns

  • Some output not properly escaped
Vulnerabilities
None known

Spreebie Barter – Ethereum Payments and Donations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spreebie Barter – Ethereum Payments and Donations Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
98 escaped
Nonce Checks
7
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped116 total outputs
Attack Surface

Spreebie Barter – Ethereum Payments and Donations Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_spreebie_barter_send_receipt_via_email_resultsincludes\spreebie-barter-admin.php:30
authwp_ajax_radio_spreebie_barter_payments_donations_ajax_add_termincludes\spreebie-barter-payments-donations.php:52
authwp_ajax_spreebie_barter_get_details_resultsspreebie-barter.php:88
noprivwp_ajax_spreebie_barter_get_details_resultsspreebie-barter.php:89
authwp_ajax_spreebie_barter_update_payment_settled_resultsspreebie-barter.php:90
noprivwp_ajax_spreebie_barter_update_payment_settled_resultsspreebie-barter.php:91
WordPress Hooks 11
actionadmin_enqueue_scriptsincludes\spreebie-barter-admin.php:27
actionadmin_menuincludes\spreebie-barter-payments-donations.php:40
actionadd_meta_boxesincludes\spreebie-barter-payments-donations.php:43
actionadd_meta_boxesincludes\spreebie-barter-payments-donations.php:46
actionadmin_enqueue_scriptsincludes\spreebie-barter-payments-donations.php:49
actionadd_meta_boxesincludes\spreebie-barter-payments-donations.php:177
actionwp_enqueue_scriptsspreebie-barter.php:82
actioninitspreebie-barter.php:505
actionadmin_menuspreebie-barter.php:508
actionadmin_initspreebie-barter.php:511
actionwidgets_initspreebie-barter.php:513
Maintenance & Trust

Spreebie Barter – Ethereum Payments and Donations Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Spreebie Barter – Ethereum Payments and Donations Developer Profile

Thabo David Klass

3 plugins · 120 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spreebie Barter – Ethereum Payments and Donations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spreebie-barter/css/style_footer.css
Version Parameters
spreebie-barter/spreebie-barter.php?ver=spreebie-barter/css/style_footer.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- The HTML code for the front-end wdiget begins here -->
Data Attributes
spreebie_barter_owner_etheruem_addressspreebie_barter_get_details_results_noncespreebie_barter_update_payment_settled_results_nonce
JS Globals
spreebie_barter_ajax_data
FAQ

Frequently Asked Questions about Spreebie Barter – Ethereum Payments and Donations