Smart Convert – Currency & Unit Conversion Security & Risk Analysis

wordpress.org/plugins/smart-convert-currency-unit-conversion

The ultimate conversion engine: 153 Currencies, 105+ Units, Custom Unit Builder, GeoIP detection, and a native Gutenberg Block with live previews.

10 active installs v1.0.1 PHP 7.2+ WP 5.4+ Updated Mar 13, 2026
currency-converterexchange-ratesgeoipmeasurementunit-converter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Convert – Currency & Unit Conversion Safe to Use in 2026?

Generally Safe

Score 100/100

Smart Convert – Currency & Unit Conversion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "smart-convert-currency-unit-conversion" plugin version 1.0.1 exhibits a generally strong security posture, with a significant number of code checks in place. The plugin demonstrates good practices by utilizing prepared statements for a majority of its SQL queries (66%) and properly escaping a high percentage of its output (95%). Nonce and capability checks are also implemented extensively, suggesting an awareness of common WordPress security vulnerabilities. There are no known CVEs associated with this plugin, and its vulnerability history is clean, which is a positive indicator.

Despite the positive aspects, the taint analysis reveals a concerning number of flows with unsanitized paths, specifically five high-severity instances. While the static analysis did not flag any dangerous functions or raw SQL queries without prepared statements, these high-severity taint flows indicate potential pathways for malicious input to be processed without adequate sanitization. This could lead to various injection vulnerabilities if not carefully handled. The presence of file operations and external HTTP requests also warrants attention, as these can sometimes be exploited if not properly secured.

In conclusion, the plugin has a solid foundation with many security best practices implemented. However, the identified high-severity taint flows with unsanitized paths represent a significant weakness that needs to be addressed. The absence of known vulnerabilities is encouraging, but the potential for exploitation via these taint flows should not be overlooked. Developers should prioritize reviewing and sanitizing these specific data flows.

Key Concerns

  • High severity taint flows with unsanitized paths
  • File operations present in code
  • External HTTP requests present in code
Vulnerabilities
None known

Smart Convert – Currency & Unit Conversion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Smart Convert – Currency & Unit Conversion Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
39 prepared
Unescaped Output
18
329 escaped
Nonce Checks
20
Capability Checks
19
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

66% prepared59 total queries

Output Escaping

95% escaped347 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

10 flows5 with unsanitized paths
ajax_check_unit_code (admin\class-smart-convert-currency-unit-conversion-admin.php:795)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Smart Convert – Currency & Unit Conversion Attack Surface

Entry Points13
Unprotected0

AJAX Handlers 12

authwp_ajax_smart_convert_currency_unit_conversion_activate_connectionadmin\class-smart-convert-currency-unit-conversion-admin.php:41
authwp_ajax_smart_convert_currency_unit_conversion_ajax_save_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:52
authwp_ajax_smart_convert_currency_unit_conversion_ajax_delete_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:53
authwp_ajax_smart_convert_currency_unit_conversion_ajax_get_edit_formadmin\class-smart-convert-currency-unit-conversion-admin.php:54
authwp_ajax_smart_convert_currency_unit_conversion_ajax_get_unit_detailsadmin\class-smart-convert-currency-unit-conversion-admin.php:57
authwp_ajax_smart_convert_currency_unit_conversion_ajax_export_unitsadmin\class-smart-convert-currency-unit-conversion-admin.php:58
authwp_ajax_smart_convert_currency_unit_conversion_ajax_import_unitsadmin\class-smart-convert-currency-unit-conversion-admin.php:59
authwp_ajax_smart_convert_currency_unit_conversion_ajax_update_ratesadmin\class-smart-convert-currency-unit-conversion-admin.php:62
authwp_ajax_smart_convert_currency_unit_conversion_ajax_update_unitsadmin\class-smart-convert-currency-unit-conversion-admin.php:63
authwp_ajax_smart_convert_currency_unit_conversion_check_unit_codeadmin\class-smart-convert-currency-unit-conversion-admin.php:66
authwp_ajax_smart_convert_currency_unit_conversion_ajax_save_custom_unitadmin\class-smart-convert-currency-unit-conversion-admin.php:67
authwp_ajax_smart_convert_currency_unit_conversion_ajax_delete_custom_unitadmin\class-smart-convert-currency-unit-conversion-admin.php:68

Shortcodes 1

[smart-convert] includes\smart-convert-currency-unit-conversion-shortcode.php:1189
WordPress Hooks 26
actionadmin_menuadmin\class-smart-convert-currency-unit-conversion-admin.php:20
actionadmin_initadmin\class-smart-convert-currency-unit-conversion-admin.php:21
actionadmin_enqueue_scriptsadmin\class-smart-convert-currency-unit-conversion-admin.php:25
actionenqueue_block_editor_assetsadmin\class-smart-convert-currency-unit-conversion-admin.php:27
actionwp_enqueue_scriptsadmin\class-smart-convert-currency-unit-conversion-admin.php:30
actioninitadmin\class-smart-convert-currency-unit-conversion-admin.php:33
actionadmin_post_smart_convert_currency_unit_conversion_manual_rates_updateadmin\class-smart-convert-currency-unit-conversion-admin.php:36
actionadmin_post_smart_convert_currency_unit_conversion_manual_units_updateadmin\class-smart-convert-currency-unit-conversion-admin.php:37
actionadmin_initadmin\class-smart-convert-currency-unit-conversion-admin.php:40
actionadmin_post_smart_convert_currency_unit_conversion_save_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:44
actionadmin_post_smart_convert_currency_unit_conversion_delete_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:45
actionadmin_post_smart_convert_currency_unit_conversion_duplicate_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:46
actionadmin_post_smart_convert_currency_unit_conversion_set_default_templateadmin\class-smart-convert-currency-unit-conversion-admin.php:47
actionadmin_post_smart_convert_currency_unit_conversion_export_templatesadmin\class-smart-convert-currency-unit-conversion-admin.php:48
actionadmin_post_smart_convert_currency_unit_conversion_import_templatesadmin\class-smart-convert-currency-unit-conversion-admin.php:49
filterload_script_translation_fileadmin\class-smart-convert-currency-unit-conversion-admin.php:74
filterpre_load_script_translationsadmin\class-smart-convert-currency-unit-conversion-admin.php:75
filtercron_schedulesincludes\smart-convert-currency-unit-conversion-cron.php:21
actionsmart_convert_currency_unit_conversion_update_currency_hookincludes\smart-convert-currency-unit-conversion-cron.php:51
actionsmart_convert_currency_unit_conversion_update_currency_retry_hookincludes\smart-convert-currency-unit-conversion-cron.php:54
actioninitincludes\smart-convert-currency-unit-conversion-cron.php:147
actioninitincludes\smart-convert-currency-unit-conversion-cron.php:350
actioninitincludes\smart-convert-currency-unit-conversion-shortcode.php:1225
actionenqueue_block_editor_assetsincludes\smart-convert-currency-unit-conversion-shortcode.php:1329
actionplugins_loadedsmart-convert-currency-unit-conversion.php:32
actionupgrader_process_completesmart-convert-currency-unit-conversion.php:481

Scheduled Events 5

smart_convert_currency_unit_conversion_update_currency_retry_hook
smart_convert_currency_unit_conversion_update_currency_hook
smart_convert_currency_unit_conversion_update_currency_hook
smart_convert_currency_unit_conversion_update_currency_hook
smart_convert_currency_unit_conversion_update_currency_hook
Maintenance & Trust

Smart Convert – Currency & Unit Conversion Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.2
Downloads208

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Smart Convert – Currency & Unit Conversion Developer Profile

Petr Novak

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Convert – Currency & Unit Conversion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-convert-currency-unit-conversion/includes/css/smart-convert-currency-unit-conversion-style.css/wp-content/plugins/smart-convert-currency-unit-conversion/includes/js/smart-convert-currency-unit-conversion-script.js
Version Parameters
smart-convert-currency-unit-conversion/includes/css/smart-convert-currency-unit-conversion-style.css?ver=smart-convert-currency-unit-conversion/includes/js/smart-convert-currency-unit-conversion-script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Smart Convert – Currency & Unit Conversion