Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Security & Risk Analysis

wordpress.org/plugins/zeno-crypto-payment-gateway

Lowest fees. USDT & USDC Payments. Supports Binance Pay and popular wallets like MetaMask, Phantom, Trust Wallet, etc...

100 active installs v1.1.1 PHP 7.4+ WP 6.0+ Updated Feb 20, 2026
accept-cryptobinance-paycryptocrypto-walletcryptocurrency
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Safe to Use in 2026?

Generally Safe

Score 100/100

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The zeno-crypto-payment-gateway plugin, at version 1.1.1, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, having no recorded vulnerabilities (CVEs), and employing capability checks for most of its code. The static analysis also reveals a high percentage of properly escaped output and no detected dangerous functions or file operations, which are significant strengths.

However, a critical concern arises from the presence of a single unprotected REST API route. This represents a direct, unauthenticated entry point into the plugin, creating a substantial attack surface that could be exploited by malicious actors. The absence of taint analysis data is also noteworthy, though this could simply mean no exploitable flows were identified by the specific tools used rather than a complete absence of risk.

Given the lack of vulnerability history, the plugin appears to have been relatively secure historically. Nevertheless, the identified unprotected REST API route is a significant weakness that elevates the overall risk. A balanced conclusion is that while the plugin has strong underlying security fundamentals in areas like data sanitization and SQL handling, the presence of an easily exploitable entry point requires immediate attention to mitigate potential threats.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
20 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

91% escaped22 total outputs
Attack Surface
1 unprotected

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/zcpg/v1/webhookincludes\class-zcpg-webhook.php:10
WordPress Hooks 9
actionrest_api_initincludes\class-zcpg-webhook.php:9
actionplugins_loadedzeno-crypto-payment-gateway.php:24
actionwoocommerce_api_zcpg_returnzeno-crypto-payment-gateway.php:36
actionadmin_noticeszeno-crypto-payment-gateway.php:38
filterwoocommerce_payment_gatewayszeno-crypto-payment-gateway.php:50
filterwoocommerce_available_payment_gatewayszeno-crypto-payment-gateway.php:56
actionwoocommerce_blocks_loadedzeno-crypto-payment-gateway.php:75
actionwoocommerce_blocks_payment_method_type_registrationzeno-crypto-payment-gateway.php:79
actionbefore_woocommerce_initzeno-crypto-payment-gateway.php:88
Maintenance & Trust

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings6
Active installs100
Developer Profile

Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more) Developer Profile

zenobank

2 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zeno-crypto-payment-gateway/assets/css/zcpg-checkout.css/wp-content/plugins/zeno-crypto-payment-gateway/assets/js/zcpg-payment.js
Script Paths
/wp-content/plugins/zeno-crypto-payment-gateway/assets/js/zcpg-payment.js
Version Parameters
zeno-crypto-payment-gateway/assets/css/zcpg-checkout.css?ver=zeno-crypto-payment-gateway/assets/js/zcpg-payment.js?ver=

HTML / DOM Fingerprints

CSS Classes
zcpg-payment-formzcpg-payment-method-titlezcpg-payment-field-labelzcpg-payment-field-inputzcpg-payment-button
HTML Comments
<!-- Zeno Crypto Payment Gateway Settings --><!-- Zeno Crypto Payment Gateway - Webhook Handler --><!-- Zeno Crypto Payment Gateway - Return Handler -->
Data Attributes
data-zcpg-order-iddata-zcpg-checkout-iddata-zcpg-verification-token
JS Globals
window.ZCPG_Paymentvar zcpg_payment_params
REST Endpoints
/zcpg/v1/webhook
FAQ

Frequently Asked Questions about Zeno Crypto Checkout for WooCommerce ( USDT, USDC, BTC and more)