
Crypto Coin Market Prices Security & Risk Analysis
wordpress.org/plugins/cryptocurrency-coin-pricesEasy to use option for setting up a bitcoin and altcoin exchange rate.
Is Crypto Coin Market Prices Safe to Use in 2026?
Generally Safe
Score 85/100Crypto Coin Market Prices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cryptocurrency-coin-prices" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it has no known historical vulnerabilities (CVEs) and its SQL queries are properly handled with prepared statements. The attack surface appears minimal with only one shortcode, and importantly, there are no unauthenticated entry points identified in the static analysis. However, significant concerns arise from the code signals. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if used with untrusted input. Furthermore, a worrying 65% of output is not properly escaped, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities. The absence of any nonce checks or capability checks on its single entry point is also a major oversight, leaving it vulnerable to various forms of attacks.
While the lack of historical CVEs might suggest a good development history, it does not negate the immediate risks identified in the static analysis. The taint analysis, showing flows with unsanitized paths, further reinforces the concern that improper handling of data could lead to vulnerabilities. The plugin's strengths lie in its clean vulnerability history and secure SQL practices. Its weaknesses are concentrated in critical areas like the use of `unserialize` without proper sanitization, inadequate output escaping, and a complete lack of authorization checks on its sole entry point, which collectively represent a significant security risk.
Key Concerns
- Dangerous function unserialize used
- Output escaping is insufficient (35% proper)
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths
Crypto Coin Market Prices Security Vulnerabilities
Crypto Coin Market Prices Release Timeline
Crypto Coin Market Prices Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Crypto Coin Market Prices Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Crypto Coin Market Prices Maintenance & Trust
Maintenance Signals
Community Trust
Crypto Coin Market Prices Alternatives
Crypto Price Widgets – CryptoWP
cryptowp
A lightweight plugin to show the latest Bitcoin, Ethereum, and other cryptocurrency widgets on your website.
Crypto Price Widgets – Live Cryptocurrency Prices by CoinLore
crypto-price-ticker-coinlore
Crypto Price Widgets by CoinLore allows you to display live cryptocurrency prices, market capitalization, and coin data directly on your WordPress web …
Live Crypto Prices
live-crypto-prices
Live cryptocurrency prices using the CoinGecko API with ticker, tables, lists, and shortcode-based display options.
Crypto Coin Market Prices Developer Profile
1 plugin · 10 total installs
How We Detect Crypto Coin Market Prices
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocurrency-coin-prices/ui/css/admin.csscryptocurrency-coin-prices/ui/css/admin.css?ver=HTML / DOM Fingerprints
cryptocurrency-coin-prices-settings-wrapdata-cryptocurrency_prices_widget_idcryptocurrency_prices_options[cryptocurrency_coin_prices]