
MetaTrader Web Terminal Security & Risk Analysis
wordpress.org/plugins/metatrader-web-terminalMetaTrader Web Terminal plugin for WordPress websites
Is MetaTrader Web Terminal Safe to Use in 2026?
Generally Safe
Score 85/100MetaTrader Web Terminal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "metatrader-web-terminal" v1.1 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively. Furthermore, the static analysis shows a low attack surface with only one shortcode and no AJAX handlers or REST API routes, minimizing potential entry points for attackers. The absence of critical or high-severity taint flows also suggests a generally clean codebase in that regard.
However, several concerns warrant attention. The lack of nonce checks and capability checks, particularly when considering its single entry point (the shortcode), is a significant weakness. This means that actions triggered by the shortcode might not be properly verified for user authorization or intentional user action, potentially leading to unintended consequences or privilege escalation if the shortcode is misused. While the output escaping is reasonably high at 85%, the 15% that is not properly escaped could still lead to cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in those outputs. The presence of file operations and external HTTP requests, without further context on their implementation, could also represent potential risks if not handled securely.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Unescaped output present (15%)
- File operations present
- External HTTP requests present
MetaTrader Web Terminal Security Vulnerabilities
MetaTrader Web Terminal Code Analysis
Output Escaping
MetaTrader Web Terminal Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
MetaTrader Web Terminal Maintenance & Trust
Maintenance Signals
Community Trust
MetaTrader Web Terminal Alternatives
Forex Trade Rates Realtime Plugin-Widget
trade-rates-realtime
One simple, light and fast widget that shows the forex rates in realtime. The quotes comes in real time from forex server or you can choose your own o …
Stock Ticker
stock-ticker
Easy add customizable moving or static ticker tapes with stock information for custom stock symbols.
Forex Calculators
fx-calculators
Integrate five essential forex calculators into your site, providing accurate financial analysis for both experienced traders and beginners.
Stock Quote
stock-quote
Insert static inline stock ticker for known exchange symbols by customizable shortcode.
Stock Charts by Public.com
stock-charts-by-public-com
Embed beautiful, dynamic stock charts within a page or post with a simple line of shortcode.
MetaTrader Web Terminal Developer Profile
2 plugins · 400 total installs
How We Detect MetaTrader Web Terminal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metatrader-web-terminal/dist/blocks.style.build.css/wp-content/plugins/metatrader-web-terminal/dist/blocks.build.js/wp-content/plugins/metatrader-web-terminal/dist/blocks.editor.build.css/wp-content/plugins/metatrader-web-terminal/css/wp-admin.css/wp-content/plugins/metatrader-web-terminal/mce/plugin.jshttps://trade.mql5.com/trade/widget.jsmetatrader-web-terminal/dist/blocks.style.build.css?ver=metatrader-web-terminal/dist/blocks.editor.build.css?ver=metatrader-web-terminal/css/wp-admin.css?ver=HTML / DOM Fingerprints
data-metatrader-widgetmetatrader_widget[metatrader