
Bitcoin and Altcoin Wallets Security & Risk Analysis
wordpress.org/plugins/walletsCustodial cryptocurrency wallets.
Is Bitcoin and Altcoin Wallets Safe to Use in 2026?
Generally Safe
Score 99/100Bitcoin and Altcoin Wallets has a strong security track record. Known vulnerabilities have been patched promptly.
The "wallets" plugin v6.4.1 presents a mixed security posture. While it demonstrates some good practices like a high percentage of SQL queries using prepared statements and a reasonable proportion of properly escaped outputs, significant concerns emerge from its attack surface and vulnerability history. The plugin exposes a large number of entry points, particularly REST API routes and AJAX handlers, with a disproportionately high percentage lacking proper authentication or permission checks. This is a critical weakness, as it makes these endpoints vulnerable to unauthorized access and potential exploitation by unauthenticated users. Furthermore, the presence of the `unserialize` function, especially without clear sanitization or context, is a known risk factor that can lead to remote code execution vulnerabilities if improperly handled. The plugin's vulnerability history, despite currently having no unpatched CVEs, includes a past medium-severity Cross-Site Scripting (XSS) vulnerability. This suggests a tendency for input sanitization issues, which, combined with the large unprotected attack surface, increases the overall risk profile. In conclusion, while the plugin has areas of strength, the substantial number of unprotected entry points and the presence of a historically problematic function like `unserialize` necessitate careful attention and immediate remediation to mitigate significant security risks.
Key Concerns
- Unprotected REST API routes
- Unprotected AJAX handlers
- Dangerous function: unserialize found
- Past medium severity XSS vulnerability
- Low percentage of proper capability checks
Bitcoin and Altcoin Wallets Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bitcoin and Altcoin Wallet <= 6.3.1 - Reflected Cross-Site Scripting
Bitcoin and Altcoin Wallets Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Bitcoin and Altcoin Wallets Attack Surface
AJAX Handlers 1
REST API Routes 19
Shortcodes 11
WordPress Hooks 173
Scheduled Events 2
Maintenance & Trust
Bitcoin and Altcoin Wallets Maintenance & Trust
Maintenance Signals
Community Trust
Bitcoin and Altcoin Wallets Alternatives
GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms
gf-gourl-add-on
This plugin enables you to use the GoUrl.io payment gateway and accept bitcoin and other altcoins directly on your Gravity Forms powered custom forms …
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
BinancePay Checkout for WooCommerce
binance-pay
Binance Pay Checkout for WooCommerce.
Bitcoin and Altcoin Wallets Developer Profile
2 plugins · 150 total installs
How We Detect Bitcoin and Altcoin Wallets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wallets/admin/assets/css/dashboard.css/wp-content/plugins/wallets/admin/assets/js/dashboard.js/wp-content/plugins/wallets/frontend/assets/css/wallets.css/wp-content/plugins/wallets/frontend/assets/js/wallets.js/wp-content/plugins/wallets/admin/assets/css/settings.css/wp-content/plugins/wallets/admin/assets/js/settings.js/wp-content/plugins/wallets/admin/assets/js/profile.js/wp-content/plugins/wallets/admin/assets/js/documentation.js+3 more/wp-content/plugins/wallets/admin/assets/js/dashboard.js/wp-content/plugins/wallets/frontend/assets/js/wallets.js/wp-content/plugins/wallets/admin/assets/js/settings.js/wp-content/plugins/wallets/admin/assets/js/profile.js/wp-content/plugins/wallets/admin/assets/js/documentation.js/wp-content/plugins/wallets/admin/assets/js/cold-storage.js+2 morewallets/admin/assets/css/dashboard.css?ver=wallets/admin/assets/js/dashboard.js?ver=wallets/frontend/assets/css/wallets.css?ver=wallets/frontend/assets/js/wallets.js?ver=wallets/admin/assets/css/settings.css?ver=wallets/admin/assets/js/settings.js?ver=wallets/admin/assets/js/profile.js?ver=wallets/admin/assets/js/documentation.js?ver=wallets/admin/assets/js/cold-storage.js?ver=wallets/admin/assets/js/pointers.js?ver=wallets/admin/assets/js/migration.js?ver=HTML / DOM Fingerprints
wallets-dashboard-widgetwallets-balancewallets-transaction-listwallets-settings-sectionwallets-form-fieldwallets-user-profile-field<!-- Wallets Admin Settings --><!-- Wallets Frontend Content --><!-- DSWallets API Endpoint -->data-wallets-currency-iddata-wallets-address-iddata-wallets-transaction-iddata-wallets-wallet-iddata-wallets-user-idDSWalletswallets_ajax_object/wp-json/wallets/v1/balance/wp-json/wallets/v1/transaction/wp-json/wallets/v1/address/wp-json/wallets/v1/wallet/wp-json/wallets/v1/settings[wallets_balance][wallets_transactions][wallets_addresses][wallets_deposit]