
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Security & Risk Analysis
wordpress.org/plugins/crypto-price-ticker-coinloreCrypto Price Widgets by CoinLore allows you to display live cryptocurrency prices, market capitalization, and coin data directly on your WordPress web …
Is Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Safe to Use in 2026?
Generally Safe
Score 100/100Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'crypto-price-ticker-coinlore' plugin v2.0 exhibits a strong security posture based on the provided static analysis. There are no detected dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped, indicating good development practices. The absence of file operations and external HTTP requests further reduces the potential attack surface. The vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development or minimal exposure.
However, there are a few areas for caution. The plugin lacks nonce checks and capability checks entirely. While the static analysis reports zero unprotected entry points (AJAX handlers, REST API routes, shortcodes), the absence of these fundamental security mechanisms is a significant concern. If any future update were to introduce new entry points or expose existing ones without proper authorization checks, it could lead to critical vulnerabilities. The bundled 'Select2' library, while not explicitly flagged as outdated, is a common component that, if not maintained, could become a vector for attack.
In conclusion, the plugin is currently in a secure state with no immediate exploitable vulnerabilities detected in this version. The development team appears to prioritize secure coding practices for SQL and output handling. The primary weakness lies in the missing nonce and capability checks, which represent a potential future risk if not addressed.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled library (Select2) potentially outdated
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Security Vulnerabilities
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Release Timeline
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Code Analysis
Bundled Libraries
Output Escaping
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Maintenance & Trust
Maintenance Signals
Community Trust
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Alternatives
Crypto Coin Market Prices
cryptocurrency-coin-prices
Easy to use option for setting up a bitcoin and altcoin exchange rate.
Cryptocurrency Widgets Pack
cryptocurrency-widgets-pack
Price ticker, table, cards, label widget for all cryptocurrencies using Coingecko API.
Crypto Price Widgets – CryptoWP
cryptowp
A lightweight plugin to show the latest Bitcoin, Ethereum, and other cryptocurrency widgets on your website.
Live Crypto Prices
live-crypto-prices
Live cryptocurrency prices using the CoinGecko API with ticker, tables, lists, and shortcode-based display options.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore Developer Profile
1 plugin · 0 total installs
How We Detect Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crypto-price-ticker-coinlore/assets/select2/js/select2.min.js/wp-content/plugins/crypto-price-ticker-coinlore/assets/select2/css/select2.min.csshttps://widget.coinlore.com/widgets/new-widget.jshttps://widget.coinlore.com/widgets/ticker-widget.jshttps://widget.coinlore.com/widgets/coinlore-list-widget.jscrypto-price-ticker-coinlore/assets/select2/js/select2.min.js?ver=crypto-price-ticker-coinlore/assets/select2/css/select2.min.css?ver=HTML / DOM Fingerprints
coinlore-coin-widgetcoinlore-priceticker-widgetcoinlore-list-widgetExit if accessed directly.data-coinlore-svgCPWC_URL[crypto-price-widgets-coinlore][crypto-price-widgets-coinlore-ticker][crypto-price-widgets-coinlore-top]