Stock Market Ticker Security & Risk Analysis

wordpress.org/plugins/stock-market-ticker

Easy to use and versatile stock market ticker, with support of over 65 world exchanges, indices, commodities and currencies.

3K active installs v1.9.27 PHP + WP 3.1+ Updated Jan 8, 2026
financial-tickerstock-market-tickerstock-tickerstocksticker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stock Market Ticker Safe to Use in 2026?

Generally Safe

Score 100/100

Stock Market Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The stock-market-ticker plugin v1.9.27 demonstrates a generally good security posture based on the provided static analysis. It exhibits a small attack surface with only one shortcode and no unprotected entry points. Notably, the plugin avoids dangerous functions, performs all SQL queries using prepared statements, and has no file operations or external HTTP requests, which are all positive security indicators. The code also includes a reasonable number of capability checks (4) and a bundled library (TinyMCE). However, a significant concern is the output escaping, with 74% of outputs properly escaped, leaving 26% potentially unescaped. This could open the door to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. Furthermore, the absence of nonce checks for the single shortcode, while not necessarily a direct vulnerability given the limited attack surface, is a missed opportunity to further harden the plugin against potential request forgery attacks. The vulnerability history is completely clean, with no recorded CVEs, which suggests a diligent development team or a lack of past significant security issues. This is a strong point, but it does not entirely negate the potential risks identified in the static analysis. In conclusion, the plugin has several strengths in its secure coding practices, but the incomplete output escaping and lack of nonce checks are areas that require attention for a more robust security profile.

Key Concerns

  • Insufficient output escaping (26% unescaped)
  • Missing nonce checks on entry points
Vulnerabilities
None known

Stock Market Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stock Market Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
67 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

74% escaped91 total outputs
Attack Surface

Stock Market Ticker Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[stock-market-ticker] stockdio_ticker_stockdioplugin.php:938
WordPress Hooks 16
actionenqueue_block_assetssrc\init.php:36
actionenqueue_block_editor_assetssrc\init.php:112
filterblock_categoriessrc\init.php:115
actioninitsrc\init.php:148
actionadmin_menustockdio_ticker_stockdioplugin.php:57
actionadmin_initstockdio_ticker_stockdioplugin.php:58
actionadmin_noticesstockdio_ticker_stockdioplugin.php:59
actionadmin_enqueue_scriptsstockdio_ticker_stockdioplugin.php:63
filtermce_external_pluginsstockdio_ticker_stockdioplugin.php:185
filtermce_buttonsstockdio_ticker_stockdioplugin.php:186
actionwp_print_scriptsstockdio_ticker_stockdioplugin.php:935
actionwp_headstockdio_ticker_stockdioplugin.php:951
filtermce_buttonsstockdio_ticker_stockdioplugin.php:1209
filtermce_external_pluginsstockdio_ticker_stockdioplugin.php:1215
actionadmin_print_stylesstockdio_ticker_widget.php:254
actionwidgets_initstockdio_ticker_widget.php:266
Maintenance & Trust

Stock Market Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version
Downloads111K

Community Trust

Rating74/100
Number of ratings15
Active installs3K
Developer Profile

Stock Market Ticker Developer Profile

Stockdio

5 plugins · 7K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
596 days
View full developer profile
Detection Fingerprints

How We Detect Stock Market Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stock-market-ticker/assets/stockdio-ticker-wp.css/wp-content/plugins/stock-market-ticker/assets/stockdio-tinymce-button.css/wp-content/plugins/stock-market-ticker/assets/Sortable.min.js/wp-content/plugins/stock-market-ticker/assets/stockdio-wp.js/wp-content/plugins/stock-market-ticker/assets/stockdio_search.css/wp-content/plugins/stock-market-ticker/assets/stockdio_search_old_version.css/wp-content/plugins/stock-market-ticker/assets/stockdio_search.js
Script Paths
assets/Sortable.min.jsassets/stockdio-wp.jsassets/stockdio_search.js
Version Parameters
stockdio-ticker-wp.css?ver=stockdio-tinymce-button.css?ver=Sortable.min.js?ver=stockdio-wp.js?ver=stockdio_search.css?ver=stockdio_search_old_version.css?ver=stockdio_search.js?ver=

HTML / DOM Fingerprints

CSS Classes
stockdio_ticker_form
JS Globals
window.stockdio_root_folderwindow.stockdio_ticker_settingswindow.stockdio_marker_ticker
FAQ

Frequently Asked Questions about Stock Market Ticker