CbrRate Security & Risk Analysis

wordpress.org/plugins/cbrrate

Show currency exchange rate Central Bank of Russia Виджет курса валют ЦБ РФ на текущий день.

40 active installs v1.1 PHP + WP 4.0+ Updated Jan 17, 2015
cbrcurrencyexchangeraterouble
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CbrRate Safe to Use in 2026?

Generally Safe

Score 85/100

CbrRate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "cbrrate" plugin version 1.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and the lack of critical or high-severity taint flows are positive indicators. Furthermore, the code appears to employ prepared statements for all SQL queries, which is a crucial best practice for preventing SQL injection vulnerabilities.

However, a significant concern arises from the complete lack of output escaping. With 11 total outputs identified and none properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content displayed to users that originates from the plugin could potentially be manipulated to execute malicious scripts in the user's browser. The absence of nonce checks and capability checks, while not directly leading to specific vulnerabilities in this analysis due to the limited attack surface, means that if new entry points are added in the future, they might not be adequately secured against unauthorized access or tampering.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

CbrRate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CbrRate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

CbrRate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioncbrrate_hourly_eventcbrrate.php:84
actionwidgets_initcbrrate.php:95
actioninitcbrrate.php:100
actionwp_enqueue_scriptscbrrate.php:104
actionparse_requestcbrrate.php:170

Scheduled Events 1

cbrrate_hourly_event
Maintenance & Trust

CbrRate Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 17, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

CbrRate Developer Profile

AndreyS.

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CbrRate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cbrrate/style.css
Version Parameters
cbrrate/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
itemcbrcbrnamecbrvaluecbrdifcbrlegend
Data Attributes
id="currency"
Shortcode Output
<div id="currency"><div class="itemcbr"><div class="cbrname"><img width="25" height="30" border="0" alt="USD" src="
FAQ

Frequently Asked Questions about CbrRate