Euro FxRef Currency Converter (by DKZR) Security & Risk Analysis

wordpress.org/plugins/euro-fxref-currency-converter

Adds the [currency] and [currency_legal] shortcodes to convert currencies based on the ECB reference exchange rates.

200 active installs v2.0.4 PHP 7.0+ WP 3.3+ Updated Dec 3, 2025
convertercurrencyforeign-exchange-conversionfx-rate-convertershortcode
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 19, 2025
Safety Verdict

Is Euro FxRef Currency Converter (by DKZR) Safe to Use in 2026?

Generally Safe

Score 99/100

Euro FxRef Currency Converter (by DKZR) has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 19, 2025Updated 4mo ago
Risk Assessment

The euro-fxref-currency-converter plugin v2.0.4 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and proper output escaping for all identified outputs are significant strengths. Furthermore, the lack of direct file operations and no critical or high-severity taint flows are positive indicators. The plugin's attack surface appears minimal with no unprotected entry points, which is a good practice.

However, there are notable areas for concern. The plugin's vulnerability history includes one known CVE, specifically a medium-severity Cross-site Scripting (XSS) vulnerability, which was last patched on 2025-06-19. While currently unpatched CVEs are zero, the presence of past XSS issues suggests a potential for input sanitization or output escaping to be insufficient in certain, perhaps undiscovered, scenarios. The lack of nonce checks and capability checks on its entry points, even though the static analysis shows no unprotected entry points, could become a risk if new functionalities are added or if the existing ones are not thoroughly protected.

In conclusion, the plugin has implemented several good security practices, particularly in handling SQL and output. The historical XSS vulnerability warrants caution, and while the current version appears clean in static analysis, the absence of nonce and capability checks on its shortcodes represents a potential weakness that could be exploited if not adequately addressed within the shortcode's internal logic. Developers should remain vigilant about input validation and output sanitization, especially considering the past XSS issue.

Key Concerns

  • Medium severity XSS vulnerability in history
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1

Euro FxRef Currency Converter (by DKZR) Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-6257medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Euro FxRef Currency Converter <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via currency Shortcode

Jun 19, 2025 Patched in 2.0.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

Euro FxRef Currency Converter (by DKZR) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Euro FxRef Currency Converter (by DKZR) Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[currency] eurofxref.php:39
[currency_legal] eurofxref.php:40
WordPress Hooks 1
actionadmin_headeurofxref.php:42
Maintenance & Trust

Euro FxRef Currency Converter (by DKZR) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.0
Downloads11K

Community Trust

Rating100/100
Number of ratings6
Active installs200
Developer Profile

Euro FxRef Currency Converter (by DKZR) Developer Profile

joost de keijzer

3 plugins · 50K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Euro FxRef Currency Converter (by DKZR)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
euro-fxref-currency-converter/eurofxref.php?ver=euro-fxref-currency-converter/inc/help.php?ver=

HTML / DOM Fingerprints

CSS Classes
eurofxref-conversion-rateeurofxref-append-stringeurofxref-prepend-string
Data Attributes
eurofxref-conversion-rateeurofxref-append-stringeurofxref-prepend-string
Shortcode Output
[currency [currency_legal
FAQ

Frequently Asked Questions about Euro FxRef Currency Converter (by DKZR)