UnusPay Crypto Payments Security & Risk Analysis

wordpress.org/plugins/unuspay-crypto-payments-for-woocommerce

THE #1 CRYPTO PAYMENT SOLUTION FOR WOOCOMMERCE — TRUSTED BY 3,000+ BUSINESSES WORLDWIDE, NOW POWERED BY AI. [youtube https://www.youtube.

10 active installs v1.0.0 PHP 7.2+ WP 6.0+ Updated Oct 19, 2025
accept-cryptobitcoincoinbasecrypto-payment-gatewayusdt
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UnusPay Crypto Payments Safe to Use in 2026?

Generally Safe

Score 100/100

UnusPay Crypto Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "unuspay-crypto-payments-for-woocommerce" v1.0.0 exhibits a concerning security posture due to its significant reliance on unprotected entry points. While the code demonstrates good practices in handling SQL queries and output escaping, the complete absence of capability checks and nonce checks on its REST API routes presents a substantial risk. This means that any authenticated user, regardless of their role or permissions, could potentially interact with these endpoints, leading to unintended actions or data manipulation if the logic within these routes is not sufficiently hardened.

The static analysis reveals a total of 4 REST API routes, all of which lack permission callbacks. This is the primary area of concern, as it creates a broad attack surface for unauthorized access. Fortunately, the code signals show no dangerous functions, all SQL queries use prepared statements, and output is properly escaped, mitigating common web vulnerabilities. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a developer with some security awareness. However, this positive history should not overshadow the critical structural weaknesses identified in the current version.

In conclusion, while the plugin has strengths in its secure coding of core functionalities like database interactions and output handling, the lack of authorization on its REST API routes is a critical flaw that needs immediate attention. The absence of this fundamental security control significantly increases the risk profile of the plugin, despite its otherwise clean vulnerability history. Addressing the unprotected REST API routes is paramount to improving its overall security.

Key Concerns

  • REST API routes without permission callbacks
  • Entry points without auth checks
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

UnusPay Crypto Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

UnusPay Crypto Payments Release Timeline

v1.0.1
v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

UnusPay Crypto Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
44 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared44 total queries

Output Escaping

100% escaped6 total outputs
Attack Surface
4 unprotected

UnusPay Crypto Payments Attack Surface

Entry Points4
Unprotected4

REST API Routes 4

POST/wp-json/unuspay/wc/checkouts/(?P<id>[\w-]+)includes/class-unuspay-wc-payments-rest.php:15
POST/wp-json/unuspay/wc/trackincludes/class-unuspay-wc-payments-rest.php:24
POST/wp-json/unuspay/wc/validateincludes/class-unuspay-wc-payments-rest.php:33
POST/wp-json/unuspay/wc/releaseincludes/class-unuspay-wc-payments-rest.php:42
WordPress Hooks 7
filterwoocommerce_payment_gatewaysincludes/class-unuspay-wc-payments.php:61
filterwoocommerce_get_registered_extended_tasksincludes/class-unuspay-wc-payments.php:78
actionwp_enqueue_scriptsincludes/class-unuspay-wc-payments.php:95
actionrest_api_initincludes/class-unuspay-wc-payments.php:114
actionadmin_initunuspay-crypto-payments-for-woocommerce.php:76
actionplugins_loadedunuspay-crypto-payments-for-woocommerce.php:95
actionbefore_woocommerce_initunuspay-crypto-payments-for-woocommerce.php:98
Maintenance & Trust

UnusPay Crypto Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 19, 2025
PHP min version7.2
Downloads734

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

UnusPay Crypto Payments Developer Profile

unustech01

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UnusPay Crypto Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unuspay-crypto-payments-for-woocommerce/assets/css/unuspay.css/wp-content/plugins/unuspay-crypto-payments-for-woocommerce/assets/js/widgets.bundle.js/wp-content/plugins/unuspay-crypto-payments-for-woocommerce/assets/js/checkout.js
Script Paths
assets/js/widgets.bundle.jsassets/js/checkout.js
Version Parameters
unuspay-crypto-payments-for-woocommerce/assets/css/unuspay.css?ver=unuspay-crypto-payments-for-woocommerce/assets/js/widgets.bundle.js?ver=unuspay-crypto-payments-for-woocommerce/assets/js/checkout.js?ver=

HTML / DOM Fingerprints

JS Globals
UNUSPAY
REST Endpoints
/wp-json/unuspay/v1/webhook
FAQ

Frequently Asked Questions about UnusPay Crypto Payments