Skloogs Trader Security & Risk Analysis

wordpress.org/plugins/skloogs-trader

This wordpress plugin allows the display of shares from the Bovespa (Brazilian Stock Exchange) and other Stock Exchanges.

10 active installs v1.1.1 PHP + WP 2.7+ Updated Jun 16, 2009
bolsabovespastockstradertrading
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Skloogs Trader Safe to Use in 2026?

Generally Safe

Score 85/100

Skloogs Trader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The skloogs-trader plugin version 1.1.1 exhibits a mixed security posture. On the positive side, the plugin appears to have a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all identified SQL queries utilize prepared statements, and there are no indications of file operations, external HTTP requests, or bundled libraries. The absence of recorded vulnerabilities in its history is also a favorable sign.

However, a significant concern arises from the complete lack of output escaping. With 38 identified output points and 0% properly escaped, this indicates a high susceptibility to Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin, if not thoroughly sanitized by other means, could be manipulated to inject malicious scripts. Additionally, the absence of nonce and capability checks, while potentially mitigated by the zero attack surface, means that if any entry points were to be discovered or introduced in future updates, they would be completely unprotected.

In conclusion, while the plugin's current attack surface is negligible and its SQL usage is secure, the critical flaw in output escaping presents a substantial risk. The vulnerability history is clean, but this could be due to the plugin's limited scope or the thoroughness of past audits. The lack of basic security checks like nonces and capability checks, coupled with unescaped output, means that even a minor oversight could lead to exploitable security issues.

Key Concerns

  • Unescaped output in 100% of outputs
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Skloogs Trader Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Skloogs Trader Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped38 total outputs
Attack Surface

Skloogs Trader Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterthe_contentskloogs-trader.php:332
actionwp_headskloogs-trader.php:333
actionadmin_headskloogs-trader.php:334
actionadmin_menuskloogs-trader.php:337
Maintenance & Trust

Skloogs Trader Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedJun 16, 2009
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Skloogs Trader Developer Profile

skloogs

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skloogs Trader

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skloogs-trader/style.css
Version Parameters
skloogs-trader/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
SkTrader
Data Attributes
data-widthdata-heightdata-sharecodedata-marketdata-perioddata-chtype+5 more
JS Globals
window.SkTRDomainwindow.SkTRVersion
Shortcode Output
<div class="SkTrader"><applet code="GeradorGrafico.class"<param name="codigo"<param name="width"
FAQ

Frequently Asked Questions about Skloogs Trader