Money92 Forex Widgets Security & Risk Analysis

wordpress.org/plugins/money92-forex-widgets

Two WordPress shortcodes that display Forex rates in PKR and a currency conversion calculator.

0 active installs v1.1.3 PHP 7.4+ WP 5.0+ Updated Mar 13, 2026
calculatorcurrencyexchange-ratesforexforex-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Money92 Forex Widgets Safe to Use in 2026?

Generally Safe

Score 100/100

Money92 Forex Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "money92-forex-widgets" plugin version 1.1.3 presents a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, not performing file operations, and exclusively using prepared statements for its SQL queries. The absence of any recorded vulnerabilities, critical or otherwise, is also a strong indicator of past diligent security practices. However, significant concerns arise from the static analysis. The plugin has a small but concerning attack surface, with one unprotected REST API route, meaning any unauthenticated user could potentially interact with it. Furthermore, a low percentage of output escaping (22%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on its entry points further exacerbates these risks.

While the plugin has no reported vulnerabilities, the identified code signals, particularly the unprotected REST API and poor output escaping, suggest a high potential for undiscovered vulnerabilities. The limited attack surface and absence of SQL injection risks are strengths, but they are significantly overshadowed by the potential for XSS and unauthorized access to the REST API. It is recommended that the unprotected REST API endpoint be secured with appropriate authentication and capability checks, and that all output be properly escaped to mitigate XSS risks.

Key Concerns

  • Unprotected REST API route
  • Low output escaping percentage
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Money92 Forex Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Money92 Forex Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

22% escaped27 total outputs
Attack Surface
1 unprotected

Money92 Forex Widgets Attack Surface

Entry Points3
Unprotected1

REST API Routes 1

GET/wp-json/m92fw/v1/pkrincludes\rest-api.php:10

Shortcodes 2

[m92fw_forex_widget] shortcodes\forex-calculators-shortcodes.php:38
[m92fw_currency_calculator] shortcodes\forex-calculators-shortcodes.php:118
WordPress Hooks 4
actionadmin_menuadmin\settings-page.php:20
actionwp_enqueue_scriptsincludes\enqueue.php:34
actionwp_enqueue_scriptsincludes\enqueue.php:88
actionrest_api_initincludes\rest-api.php:20
Maintenance & Trust

Money92 Forex Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads90

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Money92 Forex Widgets Developer Profile

gettechinfinite

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Money92 Forex Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/money92-forex-widgets/assets/css/m92fw-frontend.css/wp-content/plugins/money92-forex-widgets/assets/js/m92fw-frontend.js
Script Paths
/wp-content/plugins/money92-forex-widgets/assets/js/m92fw-frontend.js
Version Parameters
money92-forex-widgets/assets/css/m92fw-frontend.css?ver=money92-forex-widgets/assets/js/m92fw-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
m92fw-forex-widgetm92fw-titlem92fw-forex-tablem92fw-currency-calculator-wrapperm92fw-calculator-inputm92fw-calculator-output
Data Attributes
data-resturl
JS Globals
m92fwData
REST Endpoints
/wp-json/m92fw/v1/pkr
Shortcode Output
[m92fw_forex_widget][m92fw_currency_calculator]
FAQ

Frequently Asked Questions about Money92 Forex Widgets