Tokenpay Payment Gateway Security & Risk Analysis

wordpress.org/plugins/tokenpay-payment-gateway

Tokenpay's latest payment processing solution. Accept payment via cryptocurrency.

10 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Dec 4, 2024
checkoutcryptocurrencygatewaypaymentswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tokenpay Payment Gateway Safe to Use in 2026?

Generally Safe

Score 92/100

Tokenpay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "tokenpay-payment-gateway" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, unsanitized taint flows, raw SQL queries, and a complete lack of critical or high-severity vulnerabilities in its history are highly positive indicators. The code also demonstrates good practices regarding output escaping, with all detected outputs being properly sanitized.

However, there are a few areas that warrant attention. The lack of capability checks on any entry points (AJAX, REST API, shortcodes) is a significant concern. While the static analysis reported zero unprotected entry points, this could be due to the absence of these specific components in the analyzed code, rather than a deliberate security measure. If these components were to be added or were present but not detected, the lack of capability checks would expose the plugin to unauthorized access and actions. The presence of file operations and an external HTTP request without further context also suggests potential areas for misuse if not handled with strict validation and sanitization.

Overall, the plugin appears to be well-developed from a secure coding perspective, with no known historical vulnerabilities and good handling of common risky areas like SQL and output. The primary weakness lies in the potential for privilege escalation or unauthorized access if entry points are introduced without proper authorization checks. The presence of file operations and external HTTP requests also introduces a theoretical risk that requires careful implementation to mitigate.

Key Concerns

  • No capability checks on entry points
  • File operations without context
  • External HTTP requests without context
Vulnerabilities
None known

Tokenpay Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tokenpay Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped15 total outputs
Attack Surface

Tokenpay Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_enqueue_scriptsincludes\Admin\Assets.php:23
actionadmin_menuincludes\Admin\Pages\Base.php:85
actionadmin_initincludes\Admin\Pages\Base.php:86
actionadmin_initincludes\Admin\Pages\Base.php:87
actionwoocommerce_blocks_payment_method_type_registrationincludes\Integration\WooBlocks\WooBlocksInit.php:24
actionwp_enqueue_scriptsincludes\Integration\WooBlocks\WooBlocksPaymentMethod.php:25
actionadmin_enqueue_scriptsincludes\Integration\WooBlocks\WooBlocksPaymentMethod.php:26
actionbefore_woocommerce_initincludes\Util\Compatibility.php:24
actionplugins_loadedtokenpay-payment-gateway.php:150
filterwoocommerce_payment_gatewaystokenpay-payment-gateway.php:152
Maintenance & Trust

Tokenpay Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 4, 2024
PHP min version7.4
Downloads852

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tokenpay Payment Gateway Developer Profile

TokenPay Team

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tokenpay Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tokenpay-payment-gateway/assets/dist/index.css/wp-content/plugins/tokenpay-payment-gateway/assets/dist/index.js
Script Paths
/wp-content/plugins/tokenpay-payment-gateway/assets/dist/index.js
Version Parameters
tokenpay-payment-gateway/assets/dist/index.css?ver=tokenpay-payment-gateway/assets/dist/index.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Tokenpay Payment Gateway