Crypto Converter ⚡ Widget Security & Risk Analysis

wordpress.org/plugins/crypto-converter-widget

Effortless ❤️ crypto/fiat conversion: ⚡ live, secure, fast, customizable WP 📟 widget—no API keys needed, completely free!

1K active installs v3.1.1 PHP 5.3+ WP 3.1+ Updated Dec 1, 2025
bitcoincoinconvertercryptocurrencywidget
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 25, 2024
Safety Verdict

Is Crypto Converter ⚡ Widget Safe to Use in 2026?

Generally Safe

Score 99/100

Crypto Converter ⚡ Widget has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 25, 2024Updated 4mo ago
Risk Assessment

The crypto-converter-widget plugin v3.1.1 exhibits a generally good security posture based on the provided static analysis. The plugin has a small attack surface consisting of two AJAX handlers, both of which appear to have authentication checks. All SQL queries use prepared statements, and output escaping is handled effectively, with 95% of outputs properly escaped. Furthermore, nonce and capability checks are implemented, indicating an awareness of security best practices. The absence of any identified taint flows with unsanitized paths is also a positive sign.

Despite these strengths, the plugin has a history of two medium severity vulnerabilities, both related to Cross-site Scripting (XSS). The most recent vulnerability was reported on March 25, 2024, and is currently unpatched. This pattern of XSS vulnerabilities, even if medium severity, suggests a potential recurring weakness in how user input is handled or neutralized before being displayed. While the current version shows improvements in sanitization and escaping, this historical context warrants caution and further investigation into the specific mechanisms that may have led to past XSS flaws.

In conclusion, while the static analysis points to a robust implementation with good security controls in place, the documented vulnerability history, particularly the recent XSS issues, represents the most significant concern. The lack of immediate unpatched vulnerabilities in the current version is reassuring, but the recurrence of XSS suggests that vigilance is still required. The plugin's overall security is solid in its current implementation, but the past indicates a potential area for more thorough security auditing.

Key Concerns

  • Recent medium severity XSS vulnerabilities
  • Historically prone to XSS vulnerabilities
Vulnerabilities
2

Crypto Converter ⚡ Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-29930medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Crypto Converter Widget <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Mar 25, 2024 Patched in 1.9.0 (5d)
CVE-2023-49150medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Crypto Converter Widget <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 28, 2023 Patched in 1.8.4 (56d)
Code Analysis
Analyzed Mar 16, 2026

Crypto Converter ⚡ Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
40 escaped
Nonce Checks
2
Capability Checks
10
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

95% escaped42 total outputs
Attack Surface

Crypto Converter ⚡ Widget Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_CCW_admin_hide_noticeincludes\ccw-admin-notices.php:29
authwp_ajax_CCW_admin_hide_noticetrunk\includes\ccw-admin-notices.php:29
WordPress Hooks 20
actionadmin_noticesincludes\ccw-admin-notices.php:28
actionadmin_noticestrunk\includes\ccw-admin-notices.php:28
actionplugins_loadedtrunk\widget_init.php:90
actioninittrunk\widget_init.php:91
actioninittrunk\widget_init.php:92
actionadmin_inittrunk\widget_init.php:98
actionadmin_menutrunk\widget_init.php:99
actionadmin_enqueue_scriptstrunk\widget_init.php:100
actionadmin_enqueue_scriptstrunk\widget_init.php:101
actionadmin_enqueue_scriptstrunk\widget_init.php:102
actionplugins_loadedtrunk\widget_init.php:437
actionplugins_loadedwidget_init.php:90
actioninitwidget_init.php:91
actioninitwidget_init.php:92
actionadmin_initwidget_init.php:98
actionadmin_menuwidget_init.php:99
actionadmin_enqueue_scriptswidget_init.php:100
actionadmin_enqueue_scriptswidget_init.php:101
actionadmin_enqueue_scriptswidget_init.php:102
actionplugins_loadedwidget_init.php:437
Maintenance & Trust

Crypto Converter ⚡ Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version5.3
Downloads44K

Community Trust

Rating92/100
Number of ratings24
Active installs1K
Developer Profile

Crypto Converter ⚡ Widget Developer Profile

falselight

9 plugins · 5K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Crypto Converter ⚡ Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crypto-converter-widget/assets/public/crypto-converter-widget.js/wp-content/plugins/crypto-converter-widget/block.js
Script Paths
/wp-content/plugins/crypto-converter-widget/assets/public/crypto-converter-widget.js/wp-content/plugins/crypto-converter-widget/block.js
Version Parameters
crypto-converter-widget/assets/public/crypto-converter-widget.js?ver=crypto-converter-widget/block.js?ver=

HTML / DOM Fingerprints

JS Globals
blockData
FAQ

Frequently Asked Questions about Crypto Converter ⚡ Widget