Precious Metals Charts and Widgets for WordPress Security & Risk Analysis

wordpress.org/plugins/precious-metals-chart-and-widgets

Precious metals widgets (intraday and historical charts, tickers, spot tables, london fixings, etc) for Gold, Silver, Platinum, and Palladium

100 active installs v1.2.10 PHP + WP 3.5.0+ Updated Feb 19, 2025
chartgoldprecious-metalspot-pricewidget
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 23, 2025
Safety Verdict

Is Precious Metals Charts and Widgets for WordPress Safe to Use in 2026?

Generally Safe

Score 91/100

Precious Metals Charts and Widgets for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 23, 2025Updated 1yr ago
Risk Assessment

The overall security posture of the 'precious-metals-chart-and-widgets' plugin v1.2.10 presents a mixed picture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, having no file operations, and making no external HTTP requests. The attack surface is relatively small, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis.

However, there are notable areas of concern. The plugin exhibits a significant weakness in output escaping, with only 44% of outputs being properly escaped. This leaves a substantial portion of dynamic content vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks is a significant security oversight, particularly concerning for any functionality that modifies data or performs sensitive actions. The vulnerability history, which includes one medium severity XSS vulnerability in the past, corroborates the output escaping issue and highlights the potential for such flaws to manifest.

While the plugin has no currently unpatched vulnerabilities and the attack surface is controlled, the high percentage of unescaped output and the lack of nonce checks represent critical potential weaknesses. Developers should prioritize addressing these output escaping issues and implementing robust nonce checks to significantly improve the plugin's security.

Key Concerns

  • High percentage of unescaped output
  • Missing nonce checks
Vulnerabilities
1

Precious Metals Charts and Widgets for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13572medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Precious Metals Charts and Widgets for WordPress <= 1.2.8 - Authenticated (Contributor+) Stored Cross-site Scripting

Jan 23, 2025 Patched in 1.2.9 (1d)
Code Analysis
Analyzed Mar 16, 2026

Precious Metals Charts and Widgets for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
17 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped39 total outputs
Attack Surface

Precious Metals Charts and Widgets for WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nfusion-widget] wp-nFusion-Widgets.php:302
WordPress Hooks 12
actioninitwp-nFusion-Widgets.php:44
actionadd_meta_boxeswp-nFusion-Widgets.php:72
actionadmin_enqueue_scriptswp-nFusion-Widgets.php:88
actionwp_enqueue_scriptswp-nFusion-Widgets.php:95
actionsave_postwp-nFusion-Widgets.php:143
actionadd_meta_boxeswp-nFusion-Widgets.php:172
filtermanage_nfusion-widgets_posts_columnswp-nFusion-Widgets.php:215
filtermanage_edit-nfusion-widgets_columnswp-nFusion-Widgets.php:223
actionmanage_nfusion-widgets_posts_custom_columnwp-nFusion-Widgets.php:226
actioninitwp-nFusion-Widgets.php:304
actionwidgets_initwp-nFusion-Widgets.php:307
actionwp_footerwp-nFusion-Widgets.php:452
Maintenance & Trust

Precious Metals Charts and Widgets for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 19, 2025
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Precious Metals Charts and Widgets for WordPress Developer Profile

nfusionsolutions

2 plugins · 200 total installs

97
trust score
Avg Security Score
96/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Precious Metals Charts and Widgets for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/precious-metals-chart-and-widgets/includes/widgets.css/wp-content/plugins/precious-metals-chart-and-widgets/includes/script.js
Script Paths
https://widgetcdn.nfusionsolutions.com/asset/static/2/common/1/js/currency-interop.min.js

HTML / DOM Fingerprints

CSS Classes
option-parameteroption-full-width
Data Attributes
id="nfusion_chart_code"name="nfusion_chart_code"id="nfusion_parameters"name="nfusion_parameters"id="nfusion_full_fidth"name="nfusion_full_fidth"+5 more
Shortcode Output
[nfusion-widget id=
FAQ

Frequently Asked Questions about Precious Metals Charts and Widgets for WordPress