
RateX ils Plugin Security & Risk Analysis
wordpress.org/plugins/ofek-nakar-ils-rateshey , this plugin provide shortcode [ratex-ils] that allow you to display ils currency convert to GBP , USD, EUR , BTC , CNY
Is RateX ils Plugin Safe to Use in 2026?
Generally Safe
Score 85/100RateX ils Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ofek-nakar-ils-rates" v1.0.0 plugin exhibits a very strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and taint flows with unsanitized paths is highly commendable. This indicates diligent coding practices and a focus on security. The plugin also has no recorded vulnerability history, further reinforcing its current security integrity.
However, the analysis does reveal some areas that, while not currently exploited or indicative of a vulnerability in this specific version, could represent potential future risks if the plugin evolves. The presence of a shortcode without explicit mention of capability checks or nonce checks raises a minor flag. While the static analysis reports 0 entry points without auth checks, the shortcode is an entry point by nature. It's important to ensure that even shortcodes are appropriately secured, especially if they interact with sensitive data or functionality. The lack of any detected nonce checks or capability checks across the board, though not an immediate vulnerability in this context, suggests a potential pattern of relying solely on WordPress's default security measures rather than implementing explicit checks within the plugin itself.
Overall, this plugin is in excellent shape with no identified vulnerabilities. The strengths lie in its clean code, secure database interactions, and proper output handling. The only minor concern is the potential for a shortcode to become an attack vector if not carefully managed, and a general observation of no explicit security checks within the plugin's code. For a version with no known issues and such clean code, the risk is extremely low.
Key Concerns
- Shortcode without explicit auth/nonce checks mentioned
- No Nonce Checks implemented in plugin code
- No Capability Checks implemented in plugin code
RateX ils Plugin Security Vulnerabilities
RateX ils Plugin Code Analysis
RateX ils Plugin Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
RateX ils Plugin Maintenance & Trust
Maintenance Signals
Community Trust
RateX ils Plugin Alternatives
MetalpriceAPI
metalpriceapi
Display live or historical precious metal prices (Gold, Silver, Platinum, Palladium, ...) in over 150+ currencies
OPSI Israel Domestic Shipments
woo-ups-pickup
UPS Israel PickUP Access Points (Stores and Lockers) for WooCommerce. Displays Live Shipping Rates based on the Shipping Address and Cart Content.
ZPT Metals
zpt-metals
A solution provided to display precious Metals(Gold, Silver, Platinum and 36+ metals) rates in the desired currencies (USD,GBP, CAD etc).
API2Cart Live Shipping 4 Woocommerce
api2cart-live-shipping-4-woocommerce
This plugin allows to use of real-time shipping rates provided by third-party shipping services.
Neuron Expert
neuron-posts
This plugin relies on the Neuron Expert API service. A Neuron Expert WordPress plugin to display user posts and more.
RateX ils Plugin Developer Profile
8 plugins · 10 total installs
How We Detect RateX ils Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ofek-nakar-ils-rates/assets/vue.js/wp-content/plugins/ofek-nakar-ils-rates/components/app.js/wp-content/plugins/ofek-nakar-ils-rates/assets/vue.js/wp-content/plugins/ofek-nakar-ils-rates/components/app.jsHTML / DOM Fingerprints
ratex-ils<div id='appvue'><ratex-ils/></div>