FX Live Prices Security & Risk Analysis

wordpress.org/plugins/fx-live-prices

FX Live Prices WordPress Plugin provides live forex rates and indicators and cross-exchange rates. Prices quote update frequency is 1-5 seconds.

200 active installs v1.0 PHP 7.0+ WP 4.9+ Updated Feb 20, 2021
cryptoforexforex-livefx-pricingwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is FX Live Prices Safe to Use in 2026?

Generally Safe

Score 85/100

FX Live Prices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The fx-live-prices v1.0 plugin demonstrates several good security practices, including the absence of dangerous functions, file operations, and external HTTP requests. All SQL queries utilize prepared statements, and the vast majority of output is properly escaped, suggesting a strong focus on preventing common web vulnerabilities. Furthermore, the plugin has no recorded vulnerability history, which generally indicates a stable and secure codebase.

However, a significant concern arises from the presence of one unprotected AJAX handler. This creates a direct entry point into the plugin's functionality that is not protected by authentication or capability checks, potentially allowing unauthenticated users to trigger sensitive actions. While taint analysis found no issues, this unprotected AJAX handler represents a critical security gap that needs immediate attention.

In conclusion, while the plugin exhibits commendable security practices in many areas, the unprotected AJAX handler is a serious flaw that significantly increases its risk profile. Addressing this single point of vulnerability would greatly improve the plugin's overall security posture.

Key Concerns

  • Unprotected AJAX handler
  • No capability checks on entry points
Vulnerabilities
None known

FX Live Prices Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FX Live Prices Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
78 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped82 total outputs
Attack Surface
1 unprotected

FX Live Prices Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_fxlive_preview_widget_ajaxinclude\functions.php:30

Shortcodes 1

[fx-widget] include\functions.php:26
WordPress Hooks 8
actionadmin_enqueue_scriptsinclude\functions.php:16
actioninitinclude\functions.php:18
filterpost_row_actionsinclude\functions.php:20
filtermanage_posts_columnsinclude\functions.php:22
actionmanage_posts_custom_columninclude\functions.php:24
actionsave_postinclude\functions.php:28
actionadd_meta_boxesinclude\functions.php:34
actionadd_meta_boxesinclude\functions.php:36
Maintenance & Trust

FX Live Prices Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 20, 2021
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

FX Live Prices Developer Profile

FCSAPI

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FX Live Prices

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fx-live-prices/assets/style.css/wp-content/plugins/fx-live-prices/assets/fx_script.js
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css
Version Parameters
fxlive-widget-style?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Forex live rates source fxpricing.com and FCSAPI -->
Data Attributes
fx-widgetfxlive-shortcode-column
JS Globals
FXLIVE_PLUGIN_VERSION
Shortcode Output
[fx-widget id=
FAQ

Frequently Asked Questions about FX Live Prices