
Stock Charts by Public.com Security & Risk Analysis
wordpress.org/plugins/stock-charts-by-public-comEmbed beautiful, dynamic stock charts within a page or post with a simple line of shortcode.
Is Stock Charts by Public.com Safe to Use in 2026?
Generally Safe
Score 85/100Stock Charts by Public.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The stock-charts-by-public-com plugin, in version 1.0.1, exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, significant concerns arise from its attack surface and code signals. Specifically, the presence of two AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions or data manipulation. The limited output escaping, with only 43% properly handled, further increases the risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers exacerbates this risk, as it allows for easier exploitation of any unescaped output. The lack of capability checks also means that actions performed via these AJAX handlers might be accessible to users without the necessary permissions.
Despite the lack of recorded CVEs and the absence of taint analysis findings, the identified code weaknesses present tangible security risks. The plugin's attack surface is small but entirely unprotected, making any vulnerabilities within these entry points particularly impactful. The reliance on external HTTP requests and file operations, while not inherently problematic, should be carefully monitored in conjunction with the other identified issues. In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the unprotected AJAX handlers and insufficient output escaping are critical security concerns that need immediate attention to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Insufficient output escaping
- Missing capability checks
Stock Charts by Public.com Security Vulnerabilities
Stock Charts by Public.com Code Analysis
Bundled Libraries
Output Escaping
Stock Charts by Public.com Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Stock Charts by Public.com Maintenance & Trust
Maintenance Signals
Community Trust
Stock Charts by Public.com Alternatives
Stock Market Ticker
stock-market-ticker
Easy to use and versatile stock market ticker, with support of over 65 world exchanges, indices, commodities and currencies.
Stock Market News
stock-market-news
WordPress plugin and widget for displaying a list of stock news for a given public company, available in several languages.
Simple Stock Charts
simple-stock-charts
Add simple, real-time stock quotes and basic charts to your WordPress site - completely free, no frills.
Stock Market Overview
stock-market-overview
At-a-glance display of stock market, with categories for Equities, Indices, Commodities and Currencies. Supports over 65 world exchanges.
Stockdio Historical Chart
stockdio-historical-chart
WordPress plugin and widget for displaying stock market live charts and technical indicators.
Stock Charts by Public.com Developer Profile
1 plugin · 40 total installs
How We Detect Stock Charts by Public.com
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stock-charts-by-public-com/styles/admin.css/wp-content/plugins/stock-charts-by-public-com/scripts/admin.js/wp-content/plugins/stock-charts-by-public-com/styles/tinymce-style.css/wp-content/plugins/stock-charts-by-public-com/scripts/tinymce-public.js/wp-content/plugins/stock-charts-by-public-com/scripts/gutenberg-public.js/wp-content/plugins/stock-charts-by-public-com/scripts/admin.js/wp-content/plugins/stock-charts-by-public-com/scripts/tinymce-public.js/wp-content/plugins/stock-charts-by-public-com/scripts/gutenberg-public.jsstock-charts-by-public-com/wp/cssstock-charts-by-public-com/wp/jsstock-charts-by-public-com/wp/gutenberg-public/jsHTML / DOM Fingerprints
pblc/wp-json/stock-charts-public/v1/fetch-stocks