ChainKitWP Crypto Token Ticker Security & Risk Analysis

wordpress.org/plugins/crypto-token-ticker

ChainKitWP Token Ticker helps display real-time cryptocurrency data on your website with simple shortcode for any token that can be found on DexScreen …

10 active installs v1.3 PHP 7.4+ WP 5.5+ Updated Aug 7, 2025
bonkcryptocryptocurrencysolanatoken-price
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ChainKitWP Crypto Token Ticker Safe to Use in 2026?

Generally Safe

Score 100/100

ChainKitWP Crypto Token Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The crypto-token-ticker plugin, v1.3, exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, proper handling of SQL queries with prepared statements, and a high percentage of properly escaped output are positive indicators. The plugin also demonstrates an awareness of security by including capability checks and a single external HTTP request, which is common for fetching external data. The vulnerability history being clean further suggests a mature and secure development process for this plugin.

However, there are a few areas that warrant attention. The lack of nonce checks on the single shortcode entry point, while not immediately leading to a detected taint flow, represents a potential weakness. If the shortcode handler performs any action that could be triggered by an unauthenticated or unauthorized user, this could be exploited. The analysis also indicates a relatively small attack surface, with only one entry point (the shortcode) and no AJAX handlers or REST API routes. This limits the immediate vectors for attack, but the lack of protective measures on that single entry point is a concern.

In conclusion, crypto-token-ticker v1.3 appears to be a securely developed plugin with a strong emphasis on data sanitization and prepared statements. Its clean vulnerability history is commendable. The primary area for improvement is ensuring that all entry points, including the shortcode, have appropriate authorization and nonce checks to prevent potential unauthorized actions, even though current taint analysis shows no immediate critical flaws.

Key Concerns

  • Missing nonce check on shortcode entry point
Vulnerabilities
None known

ChainKitWP Crypto Token Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ChainKitWP Crypto Token Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface

ChainKitWP Crypto Token Ticker Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[crypto_price] ChainKitWP-price-display.php:72
WordPress Hooks 1
actionadmin_menuChainKitWP-price-display.php:78
Maintenance & Trust

ChainKitWP Crypto Token Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 7, 2025
PHP min version7.4
Downloads373

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

ChainKitWP Crypto Token Ticker Developer Profile

ChainKitWP

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ChainKitWP Crypto Token Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<div style=" color: #fff; padding: 10px; display: block;font-size:20px; text-align:center; border-radius: 5px;"><img src=" alt=" icon" style="width: 20px; height: 20px; margin-right: 5px;"
FAQ

Frequently Asked Questions about ChainKitWP Crypto Token Ticker