
Money92 Forex Widgets Security & Risk Analysis
wordpress.org/plugins/money92-forex-widgetsTwo WordPress shortcodes that display Forex rates in PKR and a currency conversion calculator.
Is Money92 Forex Widgets Safe to Use in 2026?
Generally Safe
Score 100/100Money92 Forex Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "money92-forex-widgets" plugin version 1.1.3 presents a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, not performing file operations, and exclusively using prepared statements for its SQL queries. The absence of any recorded vulnerabilities, critical or otherwise, is also a strong indicator of past diligent security practices. However, significant concerns arise from the static analysis. The plugin has a small but concerning attack surface, with one unprotected REST API route, meaning any unauthenticated user could potentially interact with it. Furthermore, a low percentage of output escaping (22%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on its entry points further exacerbates these risks.
While the plugin has no reported vulnerabilities, the identified code signals, particularly the unprotected REST API and poor output escaping, suggest a high potential for undiscovered vulnerabilities. The limited attack surface and absence of SQL injection risks are strengths, but they are significantly overshadowed by the potential for XSS and unauthorized access to the REST API. It is recommended that the unprotected REST API endpoint be secured with appropriate authentication and capability checks, and that all output be properly escaped to mitigate XSS risks.
Key Concerns
- Unprotected REST API route
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
Money92 Forex Widgets Security Vulnerabilities
Money92 Forex Widgets Code Analysis
Output Escaping
Money92 Forex Widgets Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Money92 Forex Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Money92 Forex Widgets Alternatives
Currency Converter Widget
currency-converter-widget
Free, fast, and beautiful currency converter widget with 170+ currencies, live exchange rates, and 11 widget styles.
Currency Converter Calculator
currency-converter-calculator
❤️ Is a magic real-time and easy-to-use with beautiful UI widget. Included 195+ world currencies with popular cryptocurrencies.
Exchange Rates Widget
exchange-rates-widget
❤️ Is a magic and easy-to-use with beautiful UI widget. Included 190+ world currencies with popular cryptocurrencies.
Cryptocurrency Converter
cryptocurrency-converter
This plugin allows to add shortcode on your WordPress site and convert over 1,400 crypto currencies. [Cryptocurrency_Converter title="Your Title& …
ForexRateAPI
forexrateapi
Display live or historical foreign exchange (forex) rates in over 150+ currencies
Money92 Forex Widgets Developer Profile
2 plugins · 0 total installs
How We Detect Money92 Forex Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/money92-forex-widgets/assets/css/m92fw-frontend.css/wp-content/plugins/money92-forex-widgets/assets/js/m92fw-frontend.js/wp-content/plugins/money92-forex-widgets/assets/js/m92fw-frontend.jsmoney92-forex-widgets/assets/css/m92fw-frontend.css?ver=money92-forex-widgets/assets/js/m92fw-frontend.js?ver=HTML / DOM Fingerprints
m92fw-forex-widgetm92fw-titlem92fw-forex-tablem92fw-currency-calculator-wrapperm92fw-calculator-inputm92fw-calculator-outputdata-resturlm92fwData/wp-json/m92fw/v1/pkr[m92fw_forex_widget][m92fw_currency_calculator]