Crypto Price And Stats Security & Risk Analysis

wordpress.org/plugins/crypto-price-and-stats

Crypto Price And Stats is a WordPress plugin displays live prices and stats of crypto coins.

30 active installs v0.1.0 PHP + WP 4.0+ Updated Dec 5, 2025
coin-price-comparecryptocrypto-price-convertercrypto-widgetscryptocurrency-stats
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Crypto Price And Stats Safe to Use in 2026?

Generally Safe

Score 100/100

Crypto Price And Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "crypto-price-and-stats" plugin v0.1.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and 100% of output is properly escaped. Furthermore, no file operations or external HTTP requests are present, and no critical or high-severity taint flows were detected. The vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or a lack of past scrutiny. The plugin also appears to be lightweight in terms of attack surface, with only one shortcode and no AJAX handlers or REST API routes that would typically require authentication checks.

However, there are specific areas that warrant attention. The absence of any nonce checks or capability checks, even on the single shortcode, represents a potential weakness. While the attack surface is currently small and unprotected entry points are zero, this lack of authorization checks on the shortcode could be exploited if the shortcode's functionality were to become more complex or sensitive in future versions. The inclusion of the Select2 library, while not inherently a security flaw, could become a concern if it is an outdated version and has known vulnerabilities, which is not detailed in the provided data.

In conclusion, the plugin is currently in a secure state with good coding practices evident in its handling of SQL and output escaping. The lack of known vulnerabilities and critical taint flows is a significant positive. The primary concern lies in the complete absence of authorization checks for its sole entry point, the shortcode. While not a critical issue at this version, it's a foundational security practice that should be implemented to safeguard against future risks as the plugin evolves.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • Bundled library (Select2) - potential for outdated version
Vulnerabilities
None known

Crypto Price And Stats Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Crypto Price And Stats Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
88 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped88 total outputs
Attack Surface

Crypto Price And Stats Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[CPS-Widget] public\class-crypto-price-and-stats-public.php:101
WordPress Hooks 7
actionplugins_loadedincludes\class-crypto-price-and-stats.php:148
actionadmin_enqueue_scriptsincludes\class-crypto-price-and-stats.php:163
actionadmin_enqueue_scriptsincludes\class-crypto-price-and-stats.php:164
actionadmin_menuincludes\class-crypto-price-and-stats.php:167
actionwp_enqueue_scriptsincludes\class-crypto-price-and-stats.php:184
actionwp_enqueue_scriptsincludes\class-crypto-price-and-stats.php:185
actioninitincludes\class-crypto-price-and-stats.php:188
Maintenance & Trust

Crypto Price And Stats Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Crypto Price And Stats Developer Profile

A WP Life

61 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect Crypto Price And Stats

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crypto-price-and-stats/admin/css/crypto-price-and-stats-admin.css/wp-content/plugins/crypto-price-and-stats/admin/css/crypto-multi-select.css/wp-content/plugins/crypto-price-and-stats/admin/css/bootstrap.min.css/wp-content/plugins/crypto-price-and-stats/admin/css/select2.min.css/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.validate.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.steps.js/wp-content/plugins/crypto-price-and-stats/admin/js/multi-select.js/wp-content/plugins/crypto-price-and-stats/admin/js/select2.min.js+1 more
Script Paths
/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.validate.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.steps.js/wp-content/plugins/crypto-price-and-stats/admin/js/multi-select.js/wp-content/plugins/crypto-price-and-stats/admin/js/select2.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/main.js
Version Parameters
crypto-price-and-stats/admin/css/crypto-price-and-stats-admin.css?ver=crypto-price-and-stats/admin/css/crypto-multi-select.css?ver=crypto-price-and-stats/admin/css/bootstrap.min.css?ver=crypto-price-and-stats/admin/css/select2.min.css?ver=crypto-price-and-stats/admin/js/jquery.validate.min.js?ver=crypto-price-and-stats/admin/js/jquery.steps.js?ver=crypto-price-and-stats/admin/js/multi-select.js?ver=crypto-price-and-stats/admin/js/select2.min.js?ver=crypto-price-and-stats/admin/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
crypto_stats_page
Data Attributes
data-plugin-name="Crypto_Price_And_Stats"
FAQ

Frequently Asked Questions about Crypto Price And Stats