Currency Converter Widget ⚡ PRO Security & Risk Analysis

wordpress.org/plugins/currency-converter-widget-pro

Currency Converter Widget ⚡ PRO: Free, easy, beautiful UI, real-time multi-currency calculation, full features.

400 active installs v1.0.8 PHP 5.3+ WP 3.1+ Updated Dec 1, 2025
convertercurrency-calculatorcurrency-convertercurrency-exchange
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Currency Converter Widget ⚡ PRO Safe to Use in 2026?

Generally Safe

Score 99/100

Currency Converter Widget ⚡ PRO has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024Updated 4mo ago
Risk Assessment

The "currency-converter-widget-pro" plugin version 1.0.8 exhibits a generally strong security posture based on the static analysis. The plugin utilizes prepared statements for all SQL queries and has a very high percentage of properly escaped output, indicating good development practices in these critical areas. The limited attack surface, with only one AJAX handler and no REST API routes, shortcodes, or cron events, is also a positive sign. The presence of a nonce check on the single AJAX handler further mitigates potential cross-site request forgery (CSRF) attacks. However, the absence of capability checks on the AJAX handler represents a significant concern, as it means that any authenticated user, regardless of their role or permissions, could potentially interact with this entry point.

Taint analysis shows no identified vulnerabilities, which is encouraging. Despite this, the plugin has a history of one known CVE, specifically a medium-severity cross-site scripting (XSS) vulnerability, which was recently patched. While the fact that it is no longer unpatched is positive, the presence of past XSS vulnerabilities, even if patched, suggests a potential for such issues to arise in the future if input sanitization or output escaping practices are not rigorously maintained. The bundled Select2 library, while not inherently a security risk, could become one if it's an outdated version or if it has known vulnerabilities, though this is not explicitly detailed in the provided data.

In conclusion, the plugin demonstrates good adherence to secure coding principles regarding SQL and output escaping. The limited attack surface is also beneficial. The primary weakness lies in the lack of capability checks on its sole AJAX entry point, which poses a risk to unauthorized users within the authenticated user base. The historical XSS vulnerability, while patched, warrants ongoing vigilance. Overall, the plugin is in a relatively good state but has a specific, actionable area for improvement to achieve a more robust security posture.

Key Concerns

  • Missing capability checks on AJAX handler
  • Historical medium severity XSS vulnerability
Vulnerabilities
1

Currency Converter Widget ⚡ PRO Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11760medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Currency Converter Widget ⚡ PRO <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024 Patched in 1.0.7 (1d)
Code Analysis
Analyzed Mar 16, 2026

Currency Converter Widget ⚡ PRO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
27 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

96% escaped28 total outputs
Attack Surface

Currency Converter Widget ⚡ PRO Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_CCWP_admin_hide_noticeincludes\ccwp-admin-notices.php:27
WordPress Hooks 8
actionadmin_noticesincludes\ccwp-admin-notices.php:26
actionadmin_menuwidget_init.php:66
actionadmin_enqueue_scriptswidget_init.php:67
actionadmin_enqueue_scriptswidget_init.php:68
actionadmin_enqueue_scriptswidget_init.php:69
filterplugin_action_linkswidget_init.php:70
filterscript_loader_tagwidget_init.php:77
actionplugins_loadedwidget_init.php:192
Maintenance & Trust

Currency Converter Widget ⚡ PRO Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version5.3
Downloads8K

Community Trust

Rating100/100
Number of ratings8
Active installs400
Developer Profile

Currency Converter Widget ⚡ PRO Developer Profile

falselight

9 plugins · 5K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Currency Converter Widget ⚡ PRO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/currency-converter-widget-pro/assets/fxwidget-ccp/multi.js/wp-content/plugins/currency-converter-widget-pro/assets/fxwidget-cc/normal.js/wp-content/plugins/currency-converter-widget-pro/assets/admin/js/ccwp-notify.js/wp-content/plugins/currency-converter-widget-pro/assets/select2/js/select2.min.js/wp-content/plugins/currency-converter-widget-pro/assets/admin/css/style.css/wp-content/plugins/currency-converter-widget-pro/assets/select2/css/select2.min.css
Script Paths
assets/fxwidget-ccp/multi.jsassets/fxwidget-cc/normal.jsassets/admin/js/ccwp-notify.jsassets/select2/js/select2.min.js
Version Parameters
currency-converter-widget-pro/assets/fxwidget-ccp/multi.js?ver=currency-converter-widget-pro/assets/fxwidget-cc/normal.js?ver=currency-converter-widget-pro/assets/admin/js/ccwp-notify.js?ver=currency-converter-widget-pro/assets/select2/js/select2.min.js?ver=currency-converter-widget-pro/assets/admin/css/style.css?ver=currency-converter-widget-pro/assets/select2/css/select2.min.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Currency Converter Widget ⚡ PRO --><!-- /Currency Converter Widget ⚡ PRO -->
Data Attributes
fxwidget-ccfxwidget-ccpsignaturemain-currfromto
JS Globals
currencyConverterWidgetProWidgetAjax
Shortcode Output
<fxwidget-cc<fxwidget-ccp
FAQ

Frequently Asked Questions about Currency Converter Widget ⚡ PRO