Курс валют ПриватБанка Security & Risk Analysis

wordpress.org/plugins/exchange-rate-privatbank

Плагін дозволяє вивести курс валют від Приват Банку на сайті в за допомогою Гутенберг блока.

20 active installs v2.0 PHP + WP 5.5+ Updated Aug 24, 2023
%d0%ba%d1%83%d1%80%d1%81-%d0%b2%d0%b0%d0%bb%d1%8e%d1%82%d0%ba%d1%83%d1%80%d1%81-%d0%b2%d0%b0%d0%bb%d1%8e%d1%82-%d0%bf%d1%80%d0%b8%d0%b2%d0%b0%d1%82%d0%b1%d0%b0%d0%bd%d0%ba%d0%bf%d1%80%d0%b8%d0%b2%d0%b0%d1%82-%d0%b1%d0%b0%d0%bd%d0%ba
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Курс валют ПриватБанка Safe to Use in 2026?

Generally Safe

Score 85/100

Курс валют ПриватБанка has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'exchange-rate-privatbank' v2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin reports zero attack surface entry points, no dangerous functions, and all SQL queries utilize prepared statements, which are excellent security practices. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This indicates that any data rendered by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if the data originates from an untrusted source. Additionally, the absence of nonce checks and capability checks, while not directly exploitable given the zero attack surface, suggests a potential lack of robust authorization and integrity protection mechanisms should any entry points be discovered or introduced in future versions. The plugin also has no recorded vulnerability history, which is a positive indicator of past security diligence. Despite the absence of direct exploitable vulnerabilities in the static analysis and history, the unescaped output presents a clear, albeit potential, risk that should be addressed.

Key Concerns

  • Output escaping is not implemented
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Курс валют ПриватБанка Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Курс валют ПриватБанка Release Timeline

v2.0Current
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Курс валют ПриватБанка Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Курс валют ПриватБанка Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedexchange-rate-privatbank.php:72
actionadmin_enqueue_scriptsincludes\admin\class-admin-main.php:30
actionenqueue_block_assetsincludes\frontend\class-frontend-main.php:15
actioninitincludes\gutenberg\gutenberg-main.php:13
Maintenance & Trust

Курс валют ПриватБанка Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 24, 2023
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Курс валют ПриватБанка Developer Profile

Maksym Marko

12 plugins · 1K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
881 days
View full developer profile
Detection Fingerprints

How We Detect Курс валют ПриватБанка

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/exchange-rate-privatbank/includes/frontend/assets/css/style.css
Version Parameters
exchange-rate-privatbank/style.css?ver=exchange-rate-privatbank/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Курс валют ПриватБанка