Easy CryptoCurrency Ticker Security & Risk Analysis

wordpress.org/plugins/cc-ticker

Easy add and display current cryptocurrency prices (bitcoin, ethereum, litecoin and/or one of 1800+ others).

10 active installs v1.0.1 PHP 5.4+ WP 4.4+ Updated Dec 28, 2020
bitcoincoincryptocurrencyethereumlitecoin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy CryptoCurrency Ticker Safe to Use in 2026?

Generally Safe

Score 85/100

Easy CryptoCurrency Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "cc-ticker" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements exclusively for SQL queries, and showing a reasonably high percentage of output escaping. There are no recorded vulnerabilities in its history, suggesting a potentially stable codebase.

However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a direct pathway for unauthorized actions. The complete absence of nonce checks is particularly alarming for these AJAX endpoints, as it means any user, even unauthenticated ones, could potentially trigger these functions. While taint analysis shows no immediate critical or high severity flows, the lack of sanitization on paths and the absence of capability checks mean that any malicious input processed by these unprotected AJAX handlers could lead to unforeseen consequences, potentially including privilege escalation or other security issues. The plugin also performs file operations and makes external HTTP requests, which, combined with the unprotected entry points, could be leveraged in an attack.

In conclusion, despite a clean vulnerability history and good SQL practices, the "cc-ticker" plugin has critical security weaknesses due to unprotected AJAX handlers. The lack of authentication and nonce checks on these entry points, coupled with file operations and external requests, presents a significant risk. While no critical taint flows are identified, the potential for exploiting these unprotected endpoints is high, warranting immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks on AJAX
  • Missing capability checks
  • Unescaped output (30% of 50)
Vulnerabilities
None known

Easy CryptoCurrency Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Easy CryptoCurrency Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
7
External Requests
2
Bundled Libraries
0

Output Escaping

70% escaped50 total outputs
Attack Surface
2 unprotected

Easy CryptoCurrency Ticker Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_cct_get_coinlistcc-ticker.php:69
authwp_ajax_cct_parse_coinlistcc-ticker.php:70

Shortcodes 1

[cryptocurrency_ticker] cc-ticker.php:66
WordPress Hooks 2
actionwp_enqueue_scriptscc-ticker.php:60
actionwidgets_initinc\widget.php:145
Maintenance & Trust

Easy CryptoCurrency Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 28, 2020
PHP min version5.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy CryptoCurrency Ticker Developer Profile

Aleksandar Urošević

8 plugins · 108K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
180 days
View full developer profile
Detection Fingerprints

How We Detect Easy CryptoCurrency Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cc-ticker/assets/css/style.css
Version Parameters
cc-ticker/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cctwamountpricecurrencychangeiconoicocoinbase
Data Attributes
data-coinbase-referral-id
JS Globals
cc_ticker_params
REST Endpoints
/wp-json/cc-ticker/v1/settings
Shortcode Output
<table class="cctw"><span class="coinbase"><a href="https://www.coinbase.com/join/<span class="amount <span class="price">
FAQ

Frequently Asked Questions about Easy CryptoCurrency Ticker