Kriptomat Cryptocurrency Price Widgets Security & Risk Analysis

wordpress.org/plugins/kriptomat-cryptocurrency-price-widget

Interactive Cryptocurrency Price Tickers, Marquee and Price Calculator

10 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Aug 12, 2021
calculatorcryptomarqueetickerwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Kriptomat Cryptocurrency Price Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

Kriptomat Cryptocurrency Price Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The Kriptomat Cryptocurrency Price Widget plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper SQL query preparation, and output escaping are significant strengths. The plugin also has no recorded vulnerabilities in its history, suggesting a commitment to secure development or a lack of past discovered issues. However, there are notable areas for improvement and potential underlying risks. The lack of nonce checks and capability checks on its entry points, particularly the four shortcodes, is a significant concern. While no direct flows were identified in the taint analysis, these unprotected entry points could be leveraged in conjunction with other vulnerabilities or by exploiting the plugin's external HTTP requests to potentially introduce risks like Cross-Site Request Forgery (CSRF) or information disclosure.

The plugin relies on external HTTP requests for its functionality, which introduces a dependency on the security of external services and can be a vector for certain types of attacks if not handled carefully. The absence of any identified vulnerabilities in its history is positive but does not guarantee future security. As the plugin matures and its functionality evolves, new vulnerabilities may emerge. The overall security can be significantly enhanced by implementing proper authentication and authorization checks on all user-facing entry points. Future development should focus on addressing these missing security controls to maintain its current good standing.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • External HTTP requests without explicit security review
Vulnerabilities
None known

Kriptomat Cryptocurrency Price Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Kriptomat Cryptocurrency Price Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
10
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Kriptomat Cryptocurrency Price Widgets Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[kriptomatCalculator300x250] Kriptomat_WP_Plugin.php:2196
[kriptomatPriceTicker300x250] Kriptomat_WP_Plugin.php:2840
[kriptomatPriceTicker300x600] Kriptomat_WP_Plugin.php:3512
[kriptomatMarquee] Kriptomat_WP_Plugin.php:4069
WordPress Hooks 5
actionadmin_initKriptomat_WP_Plugin.php:120
actionwp_enqueue_scriptsKriptomat_WP_Plugin.php:131
actioninitKriptomat_WP_Plugin.php:140
actionadmin_headKriptomat_WP_Plugin.php:152
actionadmin_menuKriptomat_WP_Plugin.php:157
Maintenance & Trust

Kriptomat Cryptocurrency Price Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 12, 2021
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Kriptomat Cryptocurrency Price Widgets Developer Profile

Srdjan Mahmutovich

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kriptomat Cryptocurrency Price Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kriptomat-cryptocurrency-price-widget/js/kriptomat-widget.js/wp-content/plugins/kriptomat-cryptocurrency-price-widget/css/kriptomat-widget.css
Script Paths
/wp-content/plugins/kriptomat-cryptocurrency-price-widget/js/kriptomat-widget.js
Version Parameters
kriptomat-cryptocurrency-price-widget/js/kriptomat-widget.js?ver=kriptomat-cryptocurrency-price-widget/css/kriptomat-widget.css?ver=

HTML / DOM Fingerprints

CSS Classes
kriptomat-widgetkriptomat-price-tickerkriptomat-price-calculator
Data Attributes
data-kriptomat-api-keydata-kriptomat-widget-iddata-kriptomat-fiatdata-kriptomat-coindata-kriptomat-coinsdata-kriptomat-color-banner-background+15 more
JS Globals
kriptomatWidgetApiUrl
Shortcode Output
[kriptomat_price_widget][kriptomat_price_calculator]
FAQ

Frequently Asked Questions about Kriptomat Cryptocurrency Price Widgets