Jika.io Stock Market Widgets Security & Risk Analysis

wordpress.org/plugins/jika-stock-market-widgets

Stock Market Widgets for WordPress By Jika.io

60 active installs v1.0.0 PHP 7.0+ WP 6.4+ Updated Mar 28, 2024
financequotequotesstocksticker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jika.io Stock Market Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

Jika.io Stock Market Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'jika-stock-market-widgets' plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and properly escaping all output. Furthermore, there is no recorded vulnerability history, suggesting a history of secure development or limited exposure. The absence of dangerous functions, file operations, and bundled libraries also contributes to a favorable impression.

However, significant security concerns arise from the attack surface analysis. The plugin exposes a total of 8 entry points, with a worrying 4 of these being AJAX handlers that lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, posing a risk if they can be manipulated to perform unintended actions. While the taint analysis shows no immediate critical or high-severity issues, the lack of capability checks on any of the AJAX handlers, combined with the external HTTP request, creates a potential pathway for attackers to exploit if an attacker-controlled input can be passed to the AJAX handlers and subsequently influence the external request.

In conclusion, while the plugin excels in fundamental secure coding practices like SQL prepared statements and output escaping, the unauthenticated AJAX endpoints represent a critical weakness. This unclosed attack vector is the primary concern, and addressing it should be the immediate priority. The absence of vulnerability history is positive but does not negate the present risks.

Key Concerns

  • Unauthenticated AJAX handlers
  • AJAX handlers without capability checks
  • External HTTP request
Vulnerabilities
None known

Jika.io Stock Market Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jika.io Stock Market Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
77 escaped
Nonce Checks
7
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped77 total outputs
Attack Surface
4 unprotected

Jika.io Stock Market Widgets Attack Surface

Entry Points8
Unprotected4

AJAX Handlers 7

authwp_ajax_jika_widgets_auth_togglesrc\admin\admin.php:29
authwp_ajax_jika_widgets_auth_submitsrc\admin\admin.php:30
authwp_ajax_jika_widgets_after_paypal_subscriptionsrc\admin\admin.php:31
authwp_ajax_jika_widgets_update_trademarksrc\admin\admin.php:32
authwp_ajax_jika_widgets_update_domainsrc\admin\admin.php:33
authwp_ajax_jika_widgets_refresh_api_keysrc\utils\api_key.php:5
authwp_ajax_jika_widgets_refresh_api_key_elementorsrc\utils\api_key.php:8

Shortcodes 1

[jika_stock_widget] src\shortcode\shortcode.php:48
WordPress Hooks 13
actioninitjika-widgets.php:30
actioninitjika-widgets.php:31
actionelementor/controls/registerjika-widgets.php:35
actionelementor/widgets/registerjika-widgets.php:36
actionelementor/controls/controls_registeredjika-widgets.php:38
actionelementor/widgets/widgets_registeredjika-widgets.php:39
actionadmin_menusrc\admin\admin.php:26
actionadmin_initsrc\admin\admin.php:27
actionadmin_noticessrc\admin\admin.php:28
actionenqueue_block_editor_assetssrc\utils\api_key.php:4
actionelementor/editor/before_enqueue_scriptssrc\utils\api_key.php:7
actionsend_headerssrc\utils\header.php:7
filterwp_headerssrc\utils\header.php:11
Maintenance & Trust

Jika.io Stock Market Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 28, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Jika.io Stock Market Widgets Developer Profile

jikaio

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jika.io Stock Market Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jika-stock-market-widgets/build/elementor/assets/icons.css/wp-content/plugins/jika-stock-market-widgets/build/utils/wp_api.php/wp-content/plugins/jika-stock-market-widgets/build/utils/api_key.php/wp-content/plugins/jika-stock-market-widgets/build/utils/header.php/wp-content/plugins/jika-stock-market-widgets/build/blocks/blocks.php/wp-content/plugins/jika-stock-market-widgets/build/admin/admin.php/wp-content/plugins/jika-stock-market-widgets/build/shortcode/shortcode.php/wp-content/plugins/jika-stock-market-widgets/build/elementor/real-time-stock-price-chart.php+11 more
Version Parameters
jika-stock-market-widgets/build/elementor/assets/icons.css?ver=

HTML / DOM Fingerprints

CSS Classes
jika-stock-market-widget
HTML Comments
<!-- JIKA WIDGETS -->
Data Attributes
data-jika-widget-symboldata-jika-widget-typedata-jika-widget-heightdata-jika-widget-time-intervaldata-jika-widget-currency
JS Globals
window.jika_widgets_auth_togglewindow.jika_widgets_auth_submitwindow.jika_widgets_after_paypal_subscriptionwindow.jika_widgets_update_trademarkwindow.jika_widgets_update_domain
Shortcode Output
[jika_stock_chart[jika_stock_price[jika_stock_news[jika_stock_exchange_rates
FAQ

Frequently Asked Questions about Jika.io Stock Market Widgets