
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Security & Risk Analysis
wordpress.org/plugins/crypto-price-widgetsEarn 50% reward of every trading fee through referrals by adding ticker, charts, price table & calculators in your WordPress posts or pages.
Is WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Safe to Use in 2026?
Generally Safe
Score 85/100WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The crypto-price-widgets plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and the consistent use of prepared statements for SQL queries are excellent indicators. Furthermore, the high percentage of properly escaped output and the minimal number of external HTTP requests suggest good coding practices. The plugin also boasts a clean vulnerability history with no known CVEs, which is a positive sign regarding its past security diligence.
However, there are notable areas for concern. The presence of unsanitized paths in two taint flows, even without critical or high severity, indicates a potential avenue for malicious input manipulation. The complete lack of nonce checks and capability checks across all entry points (shortcodes in this case) is a significant weakness. While there are no AJAX handlers or REST API routes without authentication, shortcodes are inherently exposed and lack any authorization or CSRF protection, making them a potential target for privilege escalation or other attacks if their functionality could be manipulated.
In conclusion, while the plugin has a clean history and uses many secure coding practices, the identified taint flows and, more critically, the absence of authentication/authorization checks on its shortcode entry points present a tangible risk. Addressing these specific areas would significantly improve the plugin's overall security.
Key Concerns
- Unsanitized taint flows present
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Bundled library (DataTables) may be outdated
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Security Vulnerabilities
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Attack Surface
Shortcodes 6
WordPress Hooks 8
Maintenance & Trust
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Maintenance & Trust
Maintenance Signals
Community Trust
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Alternatives
Chainwire Integration
chainwire-integration
This plugin allows to integrate your website with MediaFuse platforms.
Meritocracy – Near-Powered Gamification Plugin for WordPress
meritocracy
Meritocracy is a Near protocol-powered gamification plugin for WordPress.
Kaspa Payments Gateway for WooCommerce
kaspa-payments-gateway-woocommerce
Accept Kaspa (KAS) cryptocurrency payments in WooCommerce with automatic order confirmation, real-time verification, and multi-currency support.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List Developer Profile
1 plugin · 10 total installs
How We Detect WazirX – Free Cryptocurrency Widgets | Price Ticker & Coin List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crypto-price-widgets/admin/css/wx-crypto-shortcodes-admin.css/wp-content/plugins/crypto-price-widgets/admin/js/wx-crypto-shortcodes-admin.jscrypto-price-widgets/admin/css/wx-crypto-shortcodes-admin.css?ver=crypto-price-widgets/admin/js/wx-crypto-shortcodes-admin.js?ver=HTML / DOM Fingerprints
wxcs-descriptionwxcs_turn_referral_onwxcs_referral_invite_codewxcs-shortcodes-description[wx-crypto-ticker][wx-crypto-price-table][wx-crypto-price-chart][wx-crypto-converter]