Spoddano – Cardano For Woocommerce Security & Risk Analysis

wordpress.org/plugins/wc-spoddano

A simple Cardano (ADA) payment gateway for Woocommerce.

20 active installs v1.2.1 PHP 7.0+ WP 5.8.0+ Updated Feb 13, 2025
cardanocryptocurrencywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spoddano – Cardano For Woocommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Spoddano – Cardano For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis, the "wc-spoddano" v1.2.1 plugin exhibits a strong security posture. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks, suggesting a well-defined and protected interface. The code also adheres to secure coding practices by exclusively using prepared statements for SQL queries and properly escaping all output. The absence of file operations and dangerous function usage further contributes to its secure design.

However, a few areas warrant attention. The presence of a single external HTTP request, while not inherently a vulnerability, represents a potential attack vector if the external service is compromised or if the request is not handled securely. Furthermore, the complete lack of nonce checks and capability checks across all code signals is a significant concern. While the current analysis indicates no unprotected entry points, this oversight means that even if new entry points were inadvertently added or if the plugin's logic evolved, they would not have these fundamental security mechanisms in place, leaving them vulnerable to CSRF attacks or unauthorized access.

The vulnerability history also shows no past issues, which is a positive indicator of developer diligence. However, the absence of historical vulnerabilities does not guarantee future security. The plugin's current lack of comprehensive authorization checks is a structural weakness that could be exploited if an attacker finds a way to interact with the plugin's code directly or indirectly without going through the defined, albeit minimal, entry points. Overall, the plugin is well-written in terms of SQL and output handling, but the lack of nonce and capability checks represents a notable risk that should be addressed.

Key Concerns

  • External HTTP requests detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Spoddano – Cardano For Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spoddano – Cardano For Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Spoddano – Cardano For Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterwoocommerce_payment_complete_order_statusinc\class-wc-payment-gateway-spoddano.php:41
actionwoocommerce_email_before_order_tableinc\class-wc-payment-gateway-spoddano.php:44
filterwoocommerce_gateway_descriptioninc\spoddano-checkout-description.php:8
actionwoocommerce_checkout_processinc\spoddano-checkout-description.php:9
actionwp_footerinc\spoddano-checkout-description.php:189
actionwoocommerce_checkout_update_order_metainc\spoddano-invoice-details.php:10
actionwoocommerce_admin_order_data_after_billing_addressinc\spoddano-invoice-details.php:11
actionwoocommerce_order_details_after_order_tableinc\spoddano-invoice-details.php:12
actionwoocommerce_email_after_order_tableinc\spoddano-invoice-details.php:13
actionwoocommerce_order_details_before_order_tableinc\spoddano-invoice-details.php:14
filterwoocommerce_payment_gatewaysspoddano__func.php:48
actionplugins_loadedspoddano__func.php:55
actionwp_enqueue_scriptsspoddano__func.php:67
Maintenance & Trust

Spoddano – Cardano For Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 13, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

Spoddano – Cardano For Woocommerce Developer Profile

stixen84

4 plugins · 140 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spoddano – Cardano For Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-spoddano/css/custom.css
Version Parameters
wc-spoddano/css/custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
spod-total-adaspod-ada-txt-tooltipspod-qrcode-imgspod-payment-panelspod-ada-txt-address
Data Attributes
id="spoddano-field-box"id="spod_total_ada"id="spodadaamount-hidden"id="spod-qrcode-panel"id="spodadaaddress"id="spodadaaddress-hidden"+6 more
JS Globals
spod_copy_ada_amountspod_copy_ada
Shortcode Output
<div id="spoddano-field-box"><p class="spod-total-ada" id="spod_total_ada">Total Amount in ADA to send: <strong><div class="spod-ada-txt-tooltip"><a href="javascript:spod_copy_ada_amount();">
FAQ

Frequently Asked Questions about Spoddano – Cardano For Woocommerce