Dynamic Currency Pricing Lite Security & Risk Analysis

wordpress.org/plugins/dynamic-currency-pricing-lite

Set product prices based on USD or EUR. The plugin automatically updates your store's prices using real-time exchange rates, protecting your prof …

0 active installs v3.0.6 PHP + WP 6.0+ Updated Unknown
currencydynamic-priceexchange-ratepricingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dynamic Currency Pricing Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Dynamic Currency Pricing Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'dynamic-currency-pricing-lite' v3.0.6 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. There are no known CVEs associated with this plugin, and the static analysis reveals no critical or high-severity issues like dangerous functions, unsanitized taint flows, or raw SQL queries. The plugin also demonstrates good practices by using prepared statements for its SQL queries and implementing nonce and capability checks where appropriate.

However, there are a few areas for concern. A significant portion of output (23%) is not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output. While the attack surface is currently zero in terms of unprotected entry points, the presence of two cron events that are not explicitly detailed for their authorization status raises a minor concern. The single external HTTP request also warrants a closer look to ensure it's being handled securely and not exposing the site to risks.

Overall, the plugin appears to be developed with security in mind, evidenced by the absence of past vulnerabilities and the implementation of common security measures. The primary weakness lies in the unescaped output, which, while not rated as critical here, is a common vector for XSS. Further investigation into the cron events and the external HTTP request would be beneficial for a complete security assessment.

Key Concerns

  • Unescaped output detected
  • External HTTP request detected
Vulnerabilities
None known

Dynamic Currency Pricing Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dynamic Currency Pricing Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
30 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

77% escaped39 total outputs
Attack Surface

Dynamic Currency Pricing Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_noticesdynamic-currency-pricing-lite.php:23
actionadmin_enqueue_scriptsdynamic-currency-pricing-lite.php:27
actionwoocommerce_product_options_pricingdynamic-currency-pricing-lite.php:28
actionwoocommerce_process_product_metadynamic-currency-pricing-lite.php:29
actionadmin_menudynamic-currency-pricing-lite.php:30
actionadmin_initdynamic-currency-pricing-lite.php:31
actiondcpl_update_rates_crondynamic-currency-pricing-lite.php:32
actionadmin_initdynamic-currency-pricing-lite.php:34
actionadmin_initdynamic-currency-pricing-lite.php:35
actionplugins_loadeddynamic-currency-pricing-lite.php:37
actionadmin_noticesdynamic-currency-pricing-lite.php:522

Scheduled Events 2

dcpl_update_rates_cron
dcpl_update_rates_cron
Maintenance & Trust

Dynamic Currency Pricing Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version
Downloads158

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Dynamic Currency Pricing Lite Developer Profile

Furkan Sezgin

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dynamic Currency Pricing Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dynamic-currency-pricing-lite/assets/css/dcpl-admin-styles.css/wp-content/plugins/dynamic-currency-pricing-lite/assets/js/dcpl-admin-product.js
Version Parameters
/assets/js/dcpl-admin-product.js?ver=3.0.6/assets/css/dcpl-admin-styles.css?ver=3.0.6

HTML / DOM Fingerprints

CSS Classes
dcpl-main-titledcpl-pro-paneldcpl-pro-griddcpl-carddcpl-card-titledcpl-card-descriptiondcpl-card-buttondcpl-settings-wrapper+905 more
Data Attributes
data-dcpl-nonce
FAQ

Frequently Asked Questions about Dynamic Currency Pricing Lite