Kades Crypto Widgets Security & Risk Analysis

wordpress.org/plugins/kades-crypto-widgets

Displays Cryptocurrency widgets. More widgets and chart to come. Crypto market data from https://www.cryptocompare.com/dev/widget/wizard/ and ICOs inf …

30 active installs v1.0.3 PHP 5.2+ WP 4.0+ Updated Mar 27, 2018
bitcoincryptocryptocurrencyethereumwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kades Crypto Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

Kades Crypto Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The security posture of the kades-crypto-widgets plugin v1.0.3, based on the provided static analysis, appears to be mixed. On the positive side, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events, leading to a very small attack surface. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, suggesting a history of responsible development or minimal public scrutiny. The absence of dangerous functions and file operations is also a good sign. However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, this leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in users' browsers. Additionally, the lack of any capability checks or nonce checks, while not directly flagged as risky due to the limited attack surface, could become a concern if new entry points are introduced in future versions without proper security considerations.

The taint analysis and attack surface metrics are encouraging, indicating no immediately obvious exploitable flows or extensive entry points. The vulnerability history also suggests a stable and secure past. However, the critical flaw in output escaping significantly undermines these strengths. The plugin's current state presents a low risk of traditional exploit vectors like SQL injection or privilege escalation due to the lack of such functionalities and historical CVEs. The primary and most immediate risk stems from unescaped output, which can lead to XSS attacks affecting users who interact with the plugin's output. A balanced conclusion is that while the plugin exhibits good practices in limiting its attack surface and avoiding known dangerous patterns, the pervasive failure to escape output is a major security weakness that requires immediate attention.

Key Concerns

  • Output escaping: 0% properly escaped
  • Capability checks: 0
  • Nonce checks: 0
Vulnerabilities
None known

Kades Crypto Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kades Crypto Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Kades Crypto Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptskades-crypto-widgets.php:19
actionwidgets_initkades-crypto-widgets.php:106
Maintenance & Trust

Kades Crypto Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 27, 2018
PHP min version5.2
Downloads21K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Kades Crypto Widgets Developer Profile

Kimi

2 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kades Crypto Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kades-crypto-widgets/css/kades-crypto.css/wp-content/plugins/kades-crypto-widgets/js/kades-crypto.js
Script Paths
/wp-content/plugins/kades-crypto-widgets/js/kades-crypto.js
Version Parameters
kades-crypto-widgets/css/kades-crypto.css?ver=kades-crypto-widgets/js/kades-crypto.js?ver=

HTML / DOM Fingerprints

CSS Classes
kades_crypto_converterkades_crypto_headerkades_crypto_tabbedkades_crypto_icos
Data Attributes
data-colordata-numdata-type
Shortcode Output
<div id="kadescrypto-converter"></div><div id="kadescrypto-header"></div><div id="kadescrypto-tabbed"></div><div class="icowatchlist_list_widget" data-color="FF9F1C" data-num="5" data-type="regular"></div>
FAQ

Frequently Asked Questions about Kades Crypto Widgets