
Cryptocurreny.id Widget Security & Risk Analysis
wordpress.org/plugins/cryptocurrency-id-widgetsCryptocurrency.id provides a benchmark price index along with arbitrage opportunitiy information for the Indonesian crypto space.
Is Cryptocurreny.id Widget Safe to Use in 2026?
Generally Safe
Score 85/100Cryptocurreny.id Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cryptocurrency-id-widgets plugin v1.1 demonstrates a generally good security posture with no known past vulnerabilities or critical static analysis findings. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Prepared statements are used for all SQL queries, and there are no bundled libraries to worry about. The limited attack surface, consisting of a single shortcode, and the lack of unprotected entry points are also positive indicators.
However, several areas raise concern. The code analysis reveals that 25% of output is not properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. This is further supported by the taint analysis, which identified two flows with unsanitized paths, though they are not flagged as critical or high severity. Crucially, the plugin lacks nonce checks and capability checks entirely, meaning that actions triggered by its shortcode are not protected against CSRF attacks or unauthorized access. The absence of these fundamental security controls on even a small attack surface is a significant weakness.
In conclusion, while the plugin's developer has implemented some good security practices, the oversight in output escaping and the complete lack of nonces and capability checks create exploitable security gaps. The absence of past vulnerabilities is a positive sign, but it does not negate the immediate risks identified in the current analysis. The plugin should be updated to address these issues to ensure a more robust security profile.
Key Concerns
- Unescaped output found
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Cryptocurreny.id Widget Security Vulnerabilities
Cryptocurreny.id Widget Code Analysis
Output Escaping
Data Flow Analysis
Cryptocurreny.id Widget Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Cryptocurreny.id Widget Maintenance & Trust
Maintenance Signals
Community Trust
Cryptocurreny.id Widget Alternatives
Bitcoin price tooltip
bitcoin-price-tooltip
Plugin will find mentions of Bitcoin in your texts and automatically add a tooltip to it with actual price in USD and EUR. No need to do any setting.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Cryptocurreny.id Widget Developer Profile
1 plugin · 0 total installs
How We Detect Cryptocurreny.id Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocurrency-id-widgets/assets/admin/css/selectize.min.css/wp-content/plugins/cryptocurrency-id-widgets/assets/admin/css/style.css/wp-content/plugins/cryptocurrency-id-widgets/assets/admin/js/vendor.min.js/wp-content/plugins/cryptocurrency-id-widgets/assets/admin/js/script.jsjs/embed.jscryptocurrency-id-widgets/assets/admin/css/selectize.min.css?ver=cryptocurrency-id-widgets/assets/admin/css/style.css?ver=cryptocurrency-id-widgets/assets/admin/js/vendor.min.js?ver=cryptocurrency-id-widgets/assets/admin/js/script.js?ver=HTML / DOM Fingerprints
cryptocurrency-id-widget-containercryptocurrency-id-widget<!-- Cryptocurrency.id Widget -->tokentypedesignthemecoinwidth+3 moreCryptocurrencyID.widget[cryptoid type="card"[cryptoid type="text"