
ITS Jewellery Price Plugin Security & Risk Analysis
wordpress.org/plugins/its-jewellery-priceITS Jewellery Price Plugin for Woocommerce helps to update prices of jewellery products. We all know that prices of jewellery products change everyday …
Is ITS Jewellery Price Plugin Safe to Use in 2026?
Generally Safe
Score 100/100ITS Jewellery Price Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "its-jewellery-price" v25.05.27T plugin exhibits a concerning security posture primarily due to a significant number of unprotected entry points. While the plugin does not appear to have a history of publicly disclosed vulnerabilities (CVEs), the static analysis reveals several areas of potential weakness that could be exploited in the absence of active exploitation.
The most striking concern is the presence of 7 AJAX handlers without any authentication or capability checks. This represents a large attack surface that is easily accessible to any authenticated user, regardless of their role or permissions, potentially leading to unauthorized actions. Furthermore, the taint analysis indicates 2 high-severity flows with unsanitized paths, suggesting that user-supplied data might be processed in a way that could lead to vulnerabilities if not handled with extreme care. The absence of nonce checks on AJAX handlers is also a critical omission, making these handlers vulnerable to CSRF attacks.
While the plugin demonstrates good practices in SQL query preparation (51% prepared) and output escaping (88%), these strengths are overshadowed by the identified security gaps. The lack of any recorded CVEs might suggest that either the plugin has been less targeted or its vulnerabilities have not been publicly disclosed. However, the identified code signals and taint flows provide clear indicators of potential risks. A balanced conclusion would be that the plugin has some good security foundations but requires immediate attention to secure its numerous unprotected entry points and address the high-severity taint flows to mitigate substantial risks.
Key Concerns
- 7 unprotected AJAX handlers
- 2 high severity taint flows
- 0 nonce checks on AJAX
- Only 2 capability checks found
- Bundled library: DataTables
ITS Jewellery Price Plugin Security Vulnerabilities
ITS Jewellery Price Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ITS Jewellery Price Plugin Attack Surface
AJAX Handlers 7
Shortcodes 2
WordPress Hooks 26
Maintenance & Trust
ITS Jewellery Price Plugin Maintenance & Trust
Maintenance Signals
Community Trust
ITS Jewellery Price Plugin Alternatives
Gold-Price
gold-price-based-on-weight
Automatically calculate WooCommerce product prices based on a global price per gram of Gold, Silver, or Platinum and the weight of each product.
Dynamic Metal Price Calculator
dynamic-metal-price-calculator
Dynamic WooCommerce jewellery pricing using live metal rates with support for karat, weight, GST, markup, wastage, shipping, and variable products.
NBP Kurs Złota
kurs-zlota-nbp
PL:Wtyczka dodaje widget z aktualnym kursem złota z Narodowego Banku Polskiego.
Sound Money Info Quotes Widget
sound-money-info-quotes-widget
A lightweight, cache-friendly ticker widget that displays sound money and precious-metals quotes (gold, silver, Goldback, Kinesis, and more).
Hesapis Market Data – Gold, Currency & Crypto Prices
hesapis-market-data-gold-currency-crypto-prices
Real-time gold prices, currency exchange rates, and cryptocurrency data widgets for WordPress. Beautiful, customizable, and easy to use.
ITS Jewellery Price Plugin Developer Profile
1 plugin · 30 total installs
How We Detect ITS Jewellery Price Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/its-jewellery-price/js/admin/its-price-breakup-admin.js/wp-content/plugins/its-jewellery-price/js/public/its-price-breakup-public.js/wp-content/plugins/its-jewellery-price/css/public/its-price-breakup-public.css/wp-content/plugins/its-jewellery-price/js/admin/its-price-breakup-admin.js/wp-content/plugins/its-jewellery-price/js/public/its-price-breakup-public.jsHTML / DOM Fingerprints
its_price_breakup_frontend_datadata-its-price-breakup-paramsits_price_breakup_frontend_data