
Cryptocurrency Shortcodes Security & Risk Analysis
wordpress.org/plugins/cryptocurrency-shortcodesRetrieves information in realtime about cryptocurrencies through our API and display them using our shortcodes. The data retrieved are made available …
Is Cryptocurrency Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Cryptocurrency Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cryptocurrency-shortcodes" plugin v0.2 presents a significant security risk primarily due to its extensive unprotected attack surface. With 12 out of 13 entry points lacking any authentication or capability checks, an unauthenticated attacker could potentially trigger these handlers. This is a major concern as it bypasses WordPress's built-in security mechanisms. While the code signals indicate the absence of dangerous functions and the use of prepared statements for SQL queries, this is overshadowed by the critical issue of 100% of outputs not being properly escaped. This lack of output escaping, combined with the unprotected entry points, creates a high risk for cross-site scripting (XSS) vulnerabilities.
Furthermore, the taint analysis revealed flows with unsanitized paths, indicating potential for path traversal or file inclusion vulnerabilities, though they are not classified as critical or high. The complete absence of nonce checks on the AJAX handlers is another critical oversight, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. The vulnerability history shows a clean slate, which is positive, but it does not mitigate the immediate risks identified in the current code analysis. Overall, while the plugin avoids some common pitfalls like raw SQL and dangerous functions, its handling of user input, output, and access control is severely lacking, making it a high-risk component for any WordPress site.
Key Concerns
- AJAX handlers without auth checks
- Outputs not properly escaped
- Flows with unsanitized paths
- File operations without sanitization context
- Nonce checks missing
- Capability checks missing
Cryptocurrency Shortcodes Security Vulnerabilities
Cryptocurrency Shortcodes Release Timeline
Cryptocurrency Shortcodes Code Analysis
Output Escaping
Data Flow Analysis
Cryptocurrency Shortcodes Attack Surface
AJAX Handlers 12
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Cryptocurrency Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Cryptocurrency Shortcodes Alternatives
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
Cryptocurrency Widgets Pack
cryptocurrency-widgets-pack
Price ticker, table, cards, label widget for all cryptocurrencies using Coingecko API.
Cryptocurrency Price Widget
cryptocurrency-price-widget
Gives you a customizable Cryptocurrency Price Widget for website with ⚡live real-time price update and flexible settings.
Cryptocurrency Widgets From Coinlib
cryptocurrency-widgets-from-coinlib
Full free cryptocurrency widget pack from Coinlib (https://coinlib.io).
Crypto Price Table
crypto-price-table
Customizable Cryptocurrency Price Table with real-time price update, marketcap and flexible settings.
Cryptocurrency Shortcodes Developer Profile
2 plugins · 0 total installs
How We Detect Cryptocurrency Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocurrency-shortcodes/assets/admin_css_crypto.css/wp-content/plugins/cryptocurrency-shortcodes/assets/admin_js_crypto.js/wp-content/plugins/cryptocurrency-shortcodes/assets/client_css_crypto.css/wp-content/plugins/cryptocurrency-shortcodes/assets/client_js_crypto.js/wp-content/plugins/cryptocurrency-shortcodes/assets/admin_js_crypto.js/wp-content/plugins/cryptocurrency-shortcodes/assets/client_js_crypto.jscryptocurrency-shortcodes/assets/admin_css_crypto.css?ver=cryptocurrency-shortcodes/assets/admin_js_crypto.js?ver=cryptocurrency-shortcodes/assets/client_css_crypto.css?ver=cryptocurrency-shortcodes/assets/client_js_crypto.js?ver=HTML / DOM Fingerprints
data-ajaxurlmyAjax