
MetalpriceAPI Security & Risk Analysis
wordpress.org/plugins/metalpriceapiDisplay live or historical precious metal prices (Gold, Silver, Platinum, Palladium, ...) in over 150+ currencies
Is MetalpriceAPI Safe to Use in 2026?
Generally Safe
Score 98/100MetalpriceAPI has a strong security track record. Known vulnerabilities have been patched promptly.
The metalpriceapi plugin v1.1.7 demonstrates a generally good security posture based on the provided static analysis. All identified entry points, including shortcodes, are protected with nonce and capability checks, indicating a commitment to secure development practices. The code adheres to best practices by using prepared statements for all SQL queries and properly escaping all output, eliminating risks associated with SQL injection and Cross-Site Scripting (XSS) originating from the plugin's own code. The absence of dangerous functions, file operations, and critical taint flows further strengthens its security profile.
Despite the strong static analysis, a single historical high-severity vulnerability related to 'Improper Control of Generation of Code' ('Code Injection') is a significant concern. While the vulnerability is listed as currently unpatched for a future date (2025-05-22), the fact that a code injection vulnerability existed in the past suggests a potential weakness in how external or user-supplied data was handled or processed. The plugin also makes three external HTTP requests, which, while not inherently insecure, introduce a dependency on external services that could be compromised or unavailable, potentially impacting functionality and indirectly security if not handled with robust error checking and validation.
In conclusion, the plugin excels in its current implementation regarding SQL, output escaping, and endpoint protection. However, the past code injection vulnerability, even if patched in newer versions, warrants caution and highlights the importance of ongoing security vigilance. The external HTTP requests represent a minor area for potential improvement in terms of resilience.
Key Concerns
- Unpatched high severity CVE (future date)
MetalpriceAPI Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MetalpriceAPI <= 1.1.4 - Authenticated (Contributor+) Remote Code Execution
MetalpriceAPI Code Analysis
Output Escaping
Data Flow Analysis
MetalpriceAPI Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
MetalpriceAPI Maintenance & Trust
Maintenance Signals
Community Trust
MetalpriceAPI Alternatives
ZPT Metals
zpt-metals
A solution provided to display precious Metals(Gold, Silver, Platinum and 36+ metals) rates in the desired currencies (USD,GBP, CAD etc).
Gold Price Live
gold-price-live
Allows you to easily use shortcode to post gold, silver, platinum and palladium spot prices (updated once daily in the morning at 8:20am New York Time …
Precious Metals Automated Product Pricing – Pro
precious-metals-automated-product-pricing-pro
Automated realtime metals spot and futures data dynamically updates product prices in your store for Gold, Silver, Platinum, and Palladium
Dynamic Metal Price Calculator
dynamic-metal-price-calculator
Dynamic WooCommerce jewellery pricing using live metal rates with support for karat, weight, GST, markup, wastage, shipping, and variable products.
Sound Money Info Quotes Widget
sound-money-info-quotes-widget
A lightweight, cache-friendly ticker widget that displays sound money and precious-metals quotes (gold, silver, Goldback, Kinesis, and more).
MetalpriceAPI Developer Profile
1 plugin · 600 total installs
How We Detect MetalpriceAPI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metalpriceapi/assets/css/frontend.css/wp-content/plugins/metalpriceapi/assets/js/frontend.jsmetalpriceapi/assets/css/frontend.css?ver=metalpriceapi/assets/js/frontend.js?ver=HTML / DOM Fingerprints
[metalpriceapi][metalpriceapi_change][metalpriceapi_carat]