
MoExRate Security & Risk Analysis
wordpress.org/plugins/moexrateShow currency rate of Moscow Exchange Виджет курса валют МБ РФ на текущий день.
Is MoExRate Safe to Use in 2026?
Generally Safe
Score 85/100MoExRate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "moexrate" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, all SQL queries are properly prepared, and there are no recorded vulnerabilities or known CVEs. This suggests a development team that is mindful of common pitfalls.
However, a significant concern arises from the complete lack of output escaping. With 12 total outputs, none of which are properly escaped, this opens the plugin to a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin without sanitization could be exploited by attackers to inject malicious scripts. Additionally, the absence of nonce and capability checks on its entry points, while seemingly having a small attack surface reported, means that if any new entry points were to be introduced in future versions, they might also be unprotected, creating an indirect risk.
Given the lack of historical vulnerabilities, it's difficult to draw strong conclusions about past security practices. However, the current static analysis highlights a critical weakness in output handling. The overall risk is moderate, primarily driven by the severe lack of output escaping, which is a common vector for significant security breaches.
Key Concerns
- 0% of output escaping
- No nonce checks
- No capability checks
MoExRate Security Vulnerabilities
MoExRate Code Analysis
Output Escaping
MoExRate Attack Surface
WordPress Hooks 10
Scheduled Events 2
Maintenance & Trust
MoExRate Maintenance & Trust
Maintenance Signals
Community Trust
MoExRate Alternatives
CbrRate
cbrrate
Show currency exchange rate Central Bank of Russia Виджет курса валют ЦБ РФ на текущий день.
Currency Converter Widget
currency-converter-widget
Free, fast, and beautiful currency converter widget with 170+ currencies, live exchange rates, and 11 widget styles.
Multi Currency, Currency Switcher, Exchange Rates for WooCommerce – Mudra
woo-exchange-rate
Allows to add exchange rates for WooCommerce store
Exchange Rates
exchange-rates
Currency Converter & Exchange Rates Widgets, easy-to-use, with beautiful UI. 🔑 No API key needed, ❤️ plug and play.
Exchange Rates Widget
exchange-rates-widget
❤️ Is a magic and easy-to-use with beautiful UI widget. Included 190+ world currencies with popular cryptocurrencies.
MoExRate Developer Profile
3 plugins · 60 total installs
How We Detect MoExRate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moexrate/img/dollar.png/wp-content/plugins/moexrate/img/euro.png/wp-content/plugins/moexrate/img/up.gif/wp-content/plugins/moexrate/img/dn.gifmoexrate/style.css?ver=1.0.0HTML / DOM Fingerprints
itemmoexmoexnamemoexvaluemoexdifmoexlegendid="currency"