
Crypto Price And Stats Security & Risk Analysis
wordpress.org/plugins/crypto-price-and-statsCrypto Price And Stats is a WordPress plugin displays live prices and stats of crypto coins.
Is Crypto Price And Stats Safe to Use in 2026?
Generally Safe
Score 100/100Crypto Price And Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "crypto-price-and-stats" plugin v0.1.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and 100% of output is properly escaped. Furthermore, no file operations or external HTTP requests are present, and no critical or high-severity taint flows were detected. The vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or a lack of past scrutiny. The plugin also appears to be lightweight in terms of attack surface, with only one shortcode and no AJAX handlers or REST API routes that would typically require authentication checks.
However, there are specific areas that warrant attention. The absence of any nonce checks or capability checks, even on the single shortcode, represents a potential weakness. While the attack surface is currently small and unprotected entry points are zero, this lack of authorization checks on the shortcode could be exploited if the shortcode's functionality were to become more complex or sensitive in future versions. The inclusion of the Select2 library, while not inherently a security flaw, could become a concern if it is an outdated version and has known vulnerabilities, which is not detailed in the provided data.
In conclusion, the plugin is currently in a secure state with good coding practices evident in its handling of SQL and output escaping. The lack of known vulnerabilities and critical taint flows is a significant positive. The primary concern lies in the complete absence of authorization checks for its sole entry point, the shortcode. While not a critical issue at this version, it's a foundational security practice that should be implemented to safeguard against future risks as the plugin evolves.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
- Bundled library (Select2) - potential for outdated version
Crypto Price And Stats Security Vulnerabilities
Crypto Price And Stats Code Analysis
Bundled Libraries
Output Escaping
Crypto Price And Stats Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Crypto Price And Stats Maintenance & Trust
Maintenance Signals
Community Trust
Crypto Price And Stats Alternatives
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
Crypto Converter
crypto-converter
Customizable crypto price converter with multiple currencies, fiat conversions, and adjustable design settings.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Coinbase Commerce Payment Gateway for WooCommerce
coinbase-commerce
Accept cryptocurrencies through Coinbase Commerce such as USDC, Ethereum, and Matic on your WooCommerce store.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Crypto Price And Stats Developer Profile
61 plugins · 64K total installs
How We Detect Crypto Price And Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crypto-price-and-stats/admin/css/crypto-price-and-stats-admin.css/wp-content/plugins/crypto-price-and-stats/admin/css/crypto-multi-select.css/wp-content/plugins/crypto-price-and-stats/admin/css/bootstrap.min.css/wp-content/plugins/crypto-price-and-stats/admin/css/select2.min.css/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.validate.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.steps.js/wp-content/plugins/crypto-price-and-stats/admin/js/multi-select.js/wp-content/plugins/crypto-price-and-stats/admin/js/select2.min.js+1 more/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.validate.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/jquery.steps.js/wp-content/plugins/crypto-price-and-stats/admin/js/multi-select.js/wp-content/plugins/crypto-price-and-stats/admin/js/select2.min.js/wp-content/plugins/crypto-price-and-stats/admin/js/main.jscrypto-price-and-stats/admin/css/crypto-price-and-stats-admin.css?ver=crypto-price-and-stats/admin/css/crypto-multi-select.css?ver=crypto-price-and-stats/admin/css/bootstrap.min.css?ver=crypto-price-and-stats/admin/css/select2.min.css?ver=crypto-price-and-stats/admin/js/jquery.validate.min.js?ver=crypto-price-and-stats/admin/js/jquery.steps.js?ver=crypto-price-and-stats/admin/js/multi-select.js?ver=crypto-price-and-stats/admin/js/select2.min.js?ver=crypto-price-and-stats/admin/js/main.js?ver=HTML / DOM Fingerprints
crypto_stats_pagedata-plugin-name="Crypto_Price_And_Stats"