NBP Kurs Złota Security & Risk Analysis

wordpress.org/plugins/kurs-zlota-nbp

PL:Wtyczka dodaje widget z aktualnym kursem złota z Narodowego Banku Polskiego.

10 active installs v1.0.0 PHP + WP 4.6+ Updated Feb 26, 2017
goldgold-pricekurs-zlotakurs-zlota-nbpzloto
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is NBP Kurs Złota Safe to Use in 2026?

Generally Safe

Score 85/100

NBP Kurs Złota has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "kurs-zlota-nbp" plugin version 1.0.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its potential attack surface. Furthermore, the code signals indicate a strong adherence to secure coding practices, with no dangerous functions identified, all SQL queries using prepared statements, and no external HTTP requests. This suggests a well-crafted plugin with a minimal risk of common vulnerabilities like SQL injection or cross-site scripting through these vectors.

However, there are notable areas for concern that detract from its otherwise strong security. The most significant weakness is the extremely low percentage (15%) of properly escaped output. This suggests that a substantial portion of user-facing output is not being sanitized, creating a high risk for Cross-Site Scripting (XSS) vulnerabilities. Additionally, the complete lack of nonce checks and capability checks, particularly concerning given the presence of file operations, opens the door for potential unauthorized actions or manipulation if any entry points were to be discovered or if the plugin evolves to include them. The vulnerability history being empty is a positive sign, but it could also indicate a lack of rigorous past security auditing or that the plugin is relatively new and hasn't been subjected to extensive real-world attacks or analysis.

In conclusion, while the "kurs-zlota-nbp" plugin has successfully avoided common vulnerabilities by limiting its attack surface and securing its database interactions, the severe lack of output escaping presents a critical risk that requires immediate attention. The absence of nonce and capability checks also warrants scrutiny, especially if the plugin's functionality is expanded. The clean vulnerability history is encouraging but should not be seen as a guarantee of future security without addressing the identified code weaknesses.

Key Concerns

  • Low percentage of properly escaped output (15%)
  • No nonce checks
  • No capability checks
  • File operations present without explicit auth checks
Vulnerabilities
None known

NBP Kurs Złota Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NBP Kurs Złota Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped13 total outputs
Attack Surface

NBP Kurs Złota Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initnbp-kurs-zlota.php:21
Maintenance & Trust

NBP Kurs Złota Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 26, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

NBP Kurs Złota Developer Profile

pawelrudnicki

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NBP Kurs Złota

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about NBP Kurs Złota