
Precious Metals Charts and Widgets for WordPress Security & Risk Analysis
wordpress.org/plugins/precious-metals-chart-and-widgetsPrecious metals widgets (intraday and historical charts, tickers, spot tables, london fixings, etc) for Gold, Silver, Platinum, and Palladium
Is Precious Metals Charts and Widgets for WordPress Safe to Use in 2026?
Generally Safe
Score 91/100Precious Metals Charts and Widgets for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The overall security posture of the 'precious-metals-chart-and-widgets' plugin v1.2.10 presents a mixed picture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, having no file operations, and making no external HTTP requests. The attack surface is relatively small, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis.
However, there are notable areas of concern. The plugin exhibits a significant weakness in output escaping, with only 44% of outputs being properly escaped. This leaves a substantial portion of dynamic content vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks is a significant security oversight, particularly concerning for any functionality that modifies data or performs sensitive actions. The vulnerability history, which includes one medium severity XSS vulnerability in the past, corroborates the output escaping issue and highlights the potential for such flaws to manifest.
While the plugin has no currently unpatched vulnerabilities and the attack surface is controlled, the high percentage of unescaped output and the lack of nonce checks represent critical potential weaknesses. Developers should prioritize addressing these output escaping issues and implementing robust nonce checks to significantly improve the plugin's security.
Key Concerns
- High percentage of unescaped output
- Missing nonce checks
Precious Metals Charts and Widgets for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Precious Metals Charts and Widgets for WordPress <= 1.2.8 - Authenticated (Contributor+) Stored Cross-site Scripting
Precious Metals Charts and Widgets for WordPress Code Analysis
Output Escaping
Precious Metals Charts and Widgets for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Precious Metals Charts and Widgets for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Precious Metals Charts and Widgets for WordPress Alternatives
Precious Metals Automated Product Pricing – Pro
precious-metals-automated-product-pricing-pro
Automated realtime metals spot and futures data dynamically updates product prices in your store for Gold, Silver, Platinum, and Palladium
Charts and Graphs for Elementor
charts-and-graphs-for-elementor
Create beautiful, interactive charts with Graphs & Charts
B Chart – Line, Bar, Pie, and Other Charts
b-chart
Create and display Data Chart on your site within a few click. Easily visualize your data!
ITS Jewellery Price Plugin
its-jewellery-price
ITS Jewellery Price Plugin for Woocommerce helps to update prices of jewellery products. We all know that prices of jewellery products change everyday …
Top Music Charts Widget
top-music-charts-widget
Displays a widget listing the top iTunes charts of your choosing.
Precious Metals Charts and Widgets for WordPress Developer Profile
2 plugins · 200 total installs
How We Detect Precious Metals Charts and Widgets for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/precious-metals-chart-and-widgets/includes/widgets.css/wp-content/plugins/precious-metals-chart-and-widgets/includes/script.jshttps://widgetcdn.nfusionsolutions.com/asset/static/2/common/1/js/currency-interop.min.jsHTML / DOM Fingerprints
option-parameteroption-full-widthid="nfusion_chart_code"name="nfusion_chart_code"id="nfusion_parameters"name="nfusion_parameters"id="nfusion_full_fidth"name="nfusion_full_fidth"+5 more[nfusion-widget id=