Hesapis Market Data – Gold, Currency & Crypto Prices Security & Risk Analysis

wordpress.org/plugins/hesapis-market-data-gold-currency-crypto-prices

Real-time gold prices, currency exchange rates, and cryptocurrency data widgets for WordPress. Beautiful, customizable, and easy to use.

0 active installs v2.4.1 PHP 7.4+ WP 5.0+ Updated Feb 14, 2026
bitcoincryptocurrency-exchangegold-priceswidgets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hesapis Market Data – Gold, Currency & Crypto Prices Safe to Use in 2026?

Generally Safe

Score 100/100

Hesapis Market Data – Gold, Currency & Crypto Prices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "hesapis-market-data-gold-currency-crypto-prices" v2.4.1 plugin exhibits a generally strong security posture based on the provided static analysis. A significant positive is the absence of any known CVEs, indicating a history of good security practices or diligent patching by the developers. Furthermore, the code analysis reveals a low number of entry points and all analyzed AJAX handlers and REST API routes appear to have authorization checks, which is a commendable practice. The plugin also demonstrates good output sanitization with 96% of outputs properly escaped and a lack of critical or high-severity taint analysis findings. However, there are areas that warrant attention. The complete lack of prepared statements for all SQL queries is a significant concern, potentially exposing the plugin to SQL injection vulnerabilities. Additionally, while the number of file operations and external HTTP requests is low, these can still be vectors for attacks if not handled with extreme care. The limited number of nonce checks might also leave certain functionalities vulnerable to Cross-Site Request Forgery (CSRF) attacks.

Key Concerns

  • Raw SQL queries without prepared statements
  • Low number of nonce checks
Vulnerabilities
None known

Hesapis Market Data – Gold, Currency & Crypto Prices Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hesapis Market Data – Gold, Currency & Crypto Prices Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
23
518 escaped
Nonce Checks
3
Capability Checks
4
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

96% escaped541 total outputs
Attack Surface

Hesapis Market Data – Gold, Currency & Crypto Prices Attack Surface

Entry Points16
Unprotected0

AJAX Handlers 4

authwp_ajax_hesapis_test_apiadmin\class-hesapis-admin.php:24
authwp_ajax_hesapis_clear_cacheadmin\class-hesapis-admin.php:25
authwp_ajax_hesapis_get_datahesapis-market-data.php:132
noprivwp_ajax_hesapis_get_datahesapis-market-data.php:133

Shortcodes 12

[hesapis_gold] includes\class-hesapis-shortcodes.php:160
[hesapis_currency] includes\class-hesapis-shortcodes.php:161
[hesapis_crypto] includes\class-hesapis-shortcodes.php:162
[hesapis_ticker] includes\class-hesapis-shortcodes.php:163
[hesapis_combined] includes\class-hesapis-shortcodes.php:164
[hesapis_converter] includes\class-hesapis-shortcodes.php:165
[hesapis_single] includes\class-hesapis-shortcodes.php:167
[hesapis_marquee] includes\class-hesapis-shortcodes.php:168
[hesapis_vertical] includes\class-hesapis-shortcodes.php:169
[hesapis_compact] includes\class-hesapis-shortcodes.php:170
[hesapis_sparkline] includes\class-hesapis-shortcodes.php:171
[hesapis] includes\class-hesapis-shortcodes.php:173
WordPress Hooks 11
actionadmin_menuadmin\class-hesapis-admin.php:21
actionadmin_initadmin\class-hesapis-admin.php:22
actionadmin_enqueue_scriptsadmin\class-hesapis-admin.php:23
actionelementor/widgets/registerelementor\class-hesapis-elementor.php:15
actionelementor/elements/categories_registeredelementor\class-hesapis-elementor.php:16
actionelementor/loadedhesapis-market-data.php:100
actioninithesapis-market-data.php:119
actionwidgets_inithesapis-market-data.php:121
actionwp_enqueue_scriptshesapis-market-data.php:124
actioninithesapis-market-data.php:127
actionhesapis_refresh_cacheincludes\class-hesapis-cache.php:54

Scheduled Events 1

hesapis_refresh_cache
Maintenance & Trust

Hesapis Market Data – Gold, Currency & Crypto Prices Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 14, 2026
PHP min version7.4
Downloads135

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hesapis Market Data – Gold, Currency & Crypto Prices Developer Profile

hesapis

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hesapis Market Data – Gold, Currency & Crypto Prices

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hesapis-market-data-gold-currency-crypto-prices/public/css/hesapis-style.css/wp-content/plugins/hesapis-market-data-gold-currency-crypto-prices/public/js/hesapis-script.js
Script Paths
/wp-content/plugins/hesapis-market-data-gold-currency-crypto-prices/public/js/hesapis-script.js
Version Parameters
hesapis-market-data-gold-currency-crypto-prices/public/css/hesapis-style.css?ver=hesapis-market-data-gold-currency-crypto-prices/public/js/hesapis-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
hesapis-widget
Data Attributes
data-hesapis-widget-type
JS Globals
hesapisData
FAQ

Frequently Asked Questions about Hesapis Market Data – Gold, Currency & Crypto Prices