WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Security & Risk Analysis

wordpress.org/plugins/crypto-price-widgets

Earn 50% reward of every trading fee through referrals by adding ticker, charts, price table & calculators in your WordPress posts or pages.

10 active installs v1.0.2 PHP 5.2+ WP 4.2+ Updated May 23, 2022
blockchaincryptocurrencywazirx
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Safe to Use in 2026?

Generally Safe

Score 85/100

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The crypto-price-widgets plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and the consistent use of prepared statements for SQL queries are excellent indicators. Furthermore, the high percentage of properly escaped output and the minimal number of external HTTP requests suggest good coding practices. The plugin also boasts a clean vulnerability history with no known CVEs, which is a positive sign regarding its past security diligence.

However, there are notable areas for concern. The presence of unsanitized paths in two taint flows, even without critical or high severity, indicates a potential avenue for malicious input manipulation. The complete lack of nonce checks and capability checks across all entry points (shortcodes in this case) is a significant weakness. While there are no AJAX handlers or REST API routes without authentication, shortcodes are inherently exposed and lack any authorization or CSRF protection, making them a potential target for privilege escalation or other attacks if their functionality could be manipulated.

In conclusion, while the plugin has a clean history and uses many secure coding practices, the identified taint flows and, more critically, the absence of authentication/authorization checks on its shortcode entry points present a tangible risk. Addressing these specific areas would significantly improve the plugin's overall security.

Key Concerns

  • Unsanitized taint flows present
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Bundled library (DataTables) may be outdated
Vulnerabilities
None known

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
74 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

99% escaped75 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
charts_get_data (public\class-wx-crypto-shortcodes-public.php:373)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[wx-crypto-ticker] includes\class-wx-crypto-shortcodes.php:184
[wx-crypto-price-table] includes\class-wx-crypto-shortcodes.php:185
[wx-crypto-price-chart] includes\class-wx-crypto-shortcodes.php:188
[wx-crypto-converter] includes\class-wx-crypto-shortcodes.php:190
[wx-crypto-return-calculator] includes\class-wx-crypto-shortcodes.php:191
[wx-crypto-pp-calculator] includes\class-wx-crypto-shortcodes.php:192
WordPress Hooks 8
actionplugins_loadedcrypto-price-widgets.php:37
actionplugins_loadedincludes\class-wx-crypto-shortcodes.php:149
actionadmin_enqueue_scriptsincludes\class-wx-crypto-shortcodes.php:164
actionadmin_enqueue_scriptsincludes\class-wx-crypto-shortcodes.php:165
actioncarbon_fields_register_fieldsincludes\class-wx-crypto-shortcodes.php:166
actionwp_enqueue_scriptsincludes\class-wx-crypto-shortcodes.php:181
actionwp_enqueue_scriptsincludes\class-wx-crypto-shortcodes.php:182
actionrest_api_initincludes\class-wx-crypto-shortcodes.php:187
Maintenance & Trust

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedMay 23, 2022
PHP min version5.2
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Developer Profile

Sunny Luthra

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crypto-price-widgets/admin/css/wx-crypto-shortcodes-admin.css/wp-content/plugins/crypto-price-widgets/admin/js/wx-crypto-shortcodes-admin.js
Version Parameters
crypto-price-widgets/admin/css/wx-crypto-shortcodes-admin.css?ver=crypto-price-widgets/admin/js/wx-crypto-shortcodes-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
wxcs-descriptionwxcs_turn_referral_onwxcs_referral_invite_codewxcs-shortcodes-description
Shortcode Output
[wx-crypto-ticker][wx-crypto-price-table][wx-crypto-price-chart][wx-crypto-converter]
FAQ

Frequently Asked Questions about WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List