
Cryptocurrency Widgets From Coinlib Security & Risk Analysis
wordpress.org/plugins/cryptocurrency-widgets-from-coinlibFull free cryptocurrency widget pack from Coinlib (https://coinlib.io).
Is Cryptocurrency Widgets From Coinlib Safe to Use in 2026?
Generally Safe
Score 85/100Cryptocurrency Widgets From Coinlib has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cryptocurrency-widgets-from-coinlib plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and there are no recorded vulnerabilities or CVEs in its history. This suggests a degree of diligence in its development and maintenance.
However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler is a critical security gap, as it represents a direct entry point that can be exploited by unauthenticated users. While the static analysis did not identify specific dangerous functions or taint flows, the lack of nonces and capability checks on this unprotected entry point means any functionality exposed through it could be abused. Furthermore, the output escaping is not consistently applied, with 33% of outputs being potentially unescaped, which could lead to cross-site scripting (XSS) vulnerabilities.
In conclusion, while the absence of known vulnerabilities and the use of prepared statements are strengths, the unprotected AJAX handler and inconsistent output escaping represent clear and present risks. The plugin's vulnerability history of zero known issues is encouraging, but it doesn't negate the identified code-level weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handler
- Inconsistent output escaping (33% unescaped)
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Cryptocurrency Widgets From Coinlib Security Vulnerabilities
Cryptocurrency Widgets From Coinlib Code Analysis
Output Escaping
Cryptocurrency Widgets From Coinlib Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Cryptocurrency Widgets From Coinlib Maintenance & Trust
Maintenance Signals
Community Trust
Cryptocurrency Widgets From Coinlib Alternatives
Cryptocurrency Widgets Pack
cryptocurrency-widgets-pack
Price ticker, table, cards, label widget for all cryptocurrencies using Coingecko API.
Cryptocurrency Price Widget
cryptocurrency-price-widget
Gives you a customizable Cryptocurrency Price Widget for website with ⚡live real-time price update and flexible settings.
Crypto Price Table
crypto-price-table
Customizable Cryptocurrency Price Table with real-time price update, marketcap and flexible settings.
Cryptocurrency Widgets – Price Ticker & Coins List
cryptocurrency-price-ticker-widget
Display cryptocurrency price ticker widget, coins live price list, table, labels & coin marketcap via shortcodes.
Cryptocurrency Ticker
cryptocurrency-ticker
Fetches, caches, and displays current cryptocurrency prices (bitcoin, ethereum, and litecoin, for now).
Cryptocurrency Widgets From Coinlib Developer Profile
1 plugin · 40 total installs
How We Detect Cryptocurrency Widgets From Coinlib
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocurrency-widgets-from-coinlib/coinlib-widget.css/wp-content/plugins/cryptocurrency-widgets-from-coinlib/js/coinlib-widget-admin.js/wp-content/plugins/cryptocurrency-widgets-from-coinlib/js/coinlib-widget-admin.jsHTML / DOM Fingerprints
coinlib-widget-selwindow.coinlib_widget_admin_params<div style="width: px; height:200px; background-color: #; overflow:hidden; box-sizing: border-box; border: 1px solid #; border-radius: 4px; text-align: right; line-height:14px; font-size: 12px; box-sizing:content-box; font-feature-settings: normal; text-size-adjust: 100%; box-shadow: inset 0 -20px 0 0 #