Cryptocoin Live Ticker Security & Risk Analysis

wordpress.org/plugins/live-ticker-cryptocoin

Display cryptocoins current price, 24 hours price change and 7 days price change on your website. You can select which coins/pairs to display.

10 active installs v1.5.2 PHP + WP + Updated May 4, 2018
bitcoinbitcoin-cashcryptocoincryptocurrencylitecoin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cryptocoin Live Ticker Safe to Use in 2026?

Generally Safe

Score 85/100

Cryptocoin Live Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'live-ticker-cryptocoin' v1.5.2 plugin exhibits a generally good security posture with a very limited attack surface and no recorded vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the plugin's exposure. Furthermore, the complete avoidance of raw SQL queries by exclusively using prepared statements is a strong security practice.

However, the static analysis reveals some areas of concern. A significant portion of output is not properly escaped, with only 24% of 41 total outputs being escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. The presence of an external HTTP request also warrants investigation to ensure it's not being made to an untrusted or vulnerable endpoint and that any data exchanged is handled securely. The lack of nonce checks and capability checks across all identified entry points (though there are none) also means that if new entry points were added in the future without proper security measures, they would be vulnerable. Overall, while the plugin's current limited attack surface and good database practices are positive, the unescaped output and external HTTP request are notable weaknesses that require attention.

Key Concerns

  • Low percentage of properly escaped output
  • Presence of external HTTP requests
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Cryptocoin Live Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cryptocoin Live Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

24% escaped41 total outputs
Attack Surface

Cryptocoin Live Ticker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initcryptocoin-live-ticker.php:157
Maintenance & Trust

Cryptocoin Live Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 4, 2018
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cryptocoin Live Ticker Developer Profile

coinalyze

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocoin Live Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-ticker-cryptocoin/css/style.css/wp-content/plugins/live-ticker-cryptocoin/js/script.js
Script Paths
/wp-content/plugins/live-ticker-cryptocoin/js/script.js
Version Parameters
live-ticker-cryptocoin/css/style.css?ver=live-ticker-cryptocoin/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
cryptocoin-live-tickerpairs-datapairs-headerpair-datapairpricepchange-24hourspchange-7days+3 more
Data Attributes
id="pair-
JS Globals
cltConfig
Shortcode Output
<div class="cryptocoin-live-ticker">
FAQ

Frequently Asked Questions about Cryptocoin Live Ticker