
Gold Price Live Security & Risk Analysis
wordpress.org/plugins/gold-price-liveAllows you to easily use shortcode to post gold, silver, platinum and palladium spot prices (updated once daily in the morning at 8:20am New York Time …
Is Gold Price Live Safe to Use in 2026?
Generally Safe
Score 85/100Gold Price Live has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gold-price-live" v20.20 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding database interactions by exclusively using prepared statements for its SQL queries, which mitigates the risk of SQL injection vulnerabilities. Furthermore, there is no recorded vulnerability history (CVEs) for this plugin, suggesting a relatively stable and well-maintained codebase.
However, several significant concerns arise from the static analysis. The plugin has a substantial attack surface with 26 shortcodes, and critically, none of these entry points appear to have any authorization or capability checks. This means any user, regardless of their role or permissions, could potentially trigger code within these shortcodes, leading to unexpected behavior or information disclosure if not properly secured internally. The complete lack of nonce checks on AJAX handlers and capability checks on other entry points further exacerbates this risk, as it leaves the plugin vulnerable to CSRF attacks and unauthorized actions. A major red flag is the fact that 100% of the total outputs are not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of 25 file operations without any indication of sanitization for paths is also a concern, potentially opening the door to directory traversal or arbitrary file read/write vulnerabilities if user input influences these operations.
In conclusion, while the absence of SQL injection risks and historical vulnerabilities are strengths, the lack of authentication/authorization checks on a large attack surface, widespread unescaped output, and potentially unsanitized file operations represent significant security weaknesses. These issues, if exploited, could lead to critical vulnerabilities like XSS and unauthorized actions.
Key Concerns
- Large attack surface with no auth checks
- No nonce checks on AJAX
- No capability checks on entry points
- 100% of outputs not properly escaped
- File operations with potential path issues
Gold Price Live Security Vulnerabilities
Gold Price Live Code Analysis
Output Escaping
Gold Price Live Attack Surface
Shortcodes 26
WordPress Hooks 3
Maintenance & Trust
Gold Price Live Maintenance & Trust
Maintenance Signals
Community Trust
Gold Price Live Alternatives
Precious Metals Automated Product Pricing – Pro
precious-metals-automated-product-pricing-pro
Automated realtime metals spot and futures data dynamically updates product prices in your store for Gold, Silver, Platinum, and Palladium
MetalpriceAPI
metalpriceapi
Display live or historical precious metal prices (Gold, Silver, Platinum, Palladium, ...) in over 150+ currencies
Gold-Price
gold-price-based-on-weight
Automatically calculate WooCommerce product prices based on a global price per gram of Gold, Silver, or Platinum and the weight of each product.
Precious Metals Charts and Widgets for WordPress
precious-metals-chart-and-widgets
Precious metals widgets (intraday and historical charts, tickers, spot tables, london fixings, etc) for Gold, Silver, Platinum, and Palladium
ZPT Metals
zpt-metals
A solution provided to display precious Metals(Gold, Silver, Platinum and 36+ metals) rates in the desired currencies (USD,GBP, CAD etc).
Gold Price Live Developer Profile
1 plugin · 300 total installs
How We Detect Gold Price Live
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
gold-price-live/js/gold-price-live.jsgold-price-live/js/gold-price-live.js?ver=HTML / DOM Fingerprints
termslivewoogflogodata-formid="200344708504044"window.gpl_options[gold_chart][gold_bid][gold_ask][gold_high]