
WCMP Cointopay Gateway Security & Risk Analysis
wordpress.org/plugins/wcmp-cointopay-gatewayA Free Payment Gateway for WC Marketplace allowing you to Pay Your Vendors Using Cointopay.
Is WCMP Cointopay Gateway Safe to Use in 2026?
Generally Safe
Score 100/100WCMP Cointopay Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wcmp-cointopay-gateway" v1.2.8 plugin exhibits a mixed security posture. While it demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, significant concerns arise from its attack surface and code signals. The presence of two AJAX handlers, both lacking authentication checks, presents a direct pathway for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating potential for malicious data to be processed without proper validation, even though these did not reach critical or high severity levels in this analysis. The plugin also has a notable percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with care. The lack of nonce and capability checks on the identified AJAX endpoints is a critical oversight that exposes the plugin to a high risk of unauthorized actions. The plugin's strengths lie in its secure database interactions and clean vulnerability history, but these are heavily overshadowed by the unprotected entry points and potential data handling issues. The overall risk is elevated due to the direct and unprotected access points for potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Improperly escaped output
- Missing nonce checks
- Missing capability checks
WCMP Cointopay Gateway Security Vulnerabilities
WCMP Cointopay Gateway Code Analysis
Output Escaping
Data Flow Analysis
WCMP Cointopay Gateway Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
WCMP Cointopay Gateway Maintenance & Trust
Maintenance Signals
Community Trust
WCMP Cointopay Gateway Alternatives
MultiVendorX Cointopay Gateway
mvx-cointopay-gateway
A Free Payment Gateway for WC Marketplace allowing you to Pay Your Vendors Using Cointopay.
Marketplace Bitcoin Gateway
marketplace-bitcoin-gateway
A Free Payment Gateway for Marketplace allowing you to Pay Your Vendors Using Bitcoin.
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors
wc-vendors
The original WooCommerce multi-vendor plugin. Easily create a WooCommerce marketplace with multi-seller, product vendor stores & vendor commissions.
Migrate to WooCommerce Multivendor Marketplace
wc-multivendor-marketplace-migration
Migrate your WC Markerplace or WC Vendors Marketplace or Dokan Multivendor or WC Product Vendors store to WooCommerce Multivendor Marketplace (WCFM Ma …
Commission Widget for Dokan
commission-widget-for-dokan
Commission Widget for Dokan displays the Vendor Commission on Dokan Vendor Dashboard.
WCMP Cointopay Gateway Developer Profile
5 plugins · 70 total installs
How We Detect WCMP Cointopay Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcmp-cointopay-gateway/assets/js/wcmp_custom_js.js/wp-content/plugins/wcmp-cointopay-gateway/assets/js/wcmp_custom_js.jsHTML / DOM Fingerprints
cointopay_alt_coinname="cointopay_alt_coin"id="cointopay_merchant_id"var ajaxurl