Stocktech Alerts Security & Risk Analysis

wordpress.org/plugins/stocktech-alerts

Stocktech Alerts and stock marketing content.

0 active installs v1.0.1 PHP + WP 3.0+ Updated Dec 30, 2022
price-alerts-and-charts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stocktech Alerts Safe to Use in 2026?

Generally Safe

Score 85/100

Stocktech Alerts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The stocktech-alerts v1.0.1 plugin exhibits a generally strong security posture, particularly in its handling of database interactions and external requests. The complete absence of SQL queries that are not properly prepared, no file operations, and no external HTTP requests are excellent indicators of good security practices and a reduced attack surface. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a commitment to security by the developers or a lack of discovered vulnerabilities.

However, there are areas that warrant attention. The static analysis reveals 59 total outputs with 71% properly escaped, meaning a significant portion (29%) of outputs are potentially unescaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is outputted without proper sanitization. Furthermore, the plugin lacks nonce checks entirely, which, while not directly tied to a specific entry point with a missing check in the provided data, is a fundamental security mechanism that should ideally be present for all sensitive actions or data processing.

In conclusion, the plugin demonstrates a good foundation with secure database and external communication practices and a clean history. The primary concerns revolve around potential XSS vulnerabilities due to incomplete output escaping and the absence of nonce checks, which represent opportunities for attackers to inject malicious scripts or exploit unintended actions. Addressing these areas would significantly enhance the plugin's overall security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
Vulnerabilities
None known

Stocktech Alerts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Stocktech Alerts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
42 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped59 total outputs
Attack Surface

Stocktech Alerts Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[stocktech-alerts] stocktech_alerts_plugin.php:390
WordPress Hooks 14
actionenqueue_block_editor_assetssrc\init.php:28
filterblock_categoriessrc\init.php:31
actioninitsrc\init.php:64
actionadmin_menustocktech_alerts_plugin.php:55
actionadmin_initstocktech_alerts_plugin.php:56
actionadmin_noticesstocktech_alerts_plugin.php:57
actionadmin_headstocktech_alerts_plugin.php:58
actionadmin_headstocktech_alerts_plugin.php:59
actionwp_print_scriptsstocktech_alerts_plugin.php:388
actionwp_headstocktech_alerts_plugin.php:402
filtermce_buttonsstocktech_alerts_plugin.php:657
filtermce_external_pluginsstocktech_alerts_plugin.php:663
actionwidgets_initstocktech_alerts_widget.php:122
actionadmin_print_stylesstocktech_alerts_widget.php:126
Maintenance & Trust

Stocktech Alerts Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 30, 2022
PHP min version
Downloads565

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Stocktech Alerts Alternatives

No alternatives data available yet.

Developer Profile

Stocktech Alerts Developer Profile

StockTech

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stocktech Alerts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stocktech-alerts/assets/stocktech-wp.css
Version Parameters
stocktech-alerts/assets/stocktech-wp.css?ver=

HTML / DOM Fingerprints

CSS Classes
stocktech_alerts_form
FAQ

Frequently Asked Questions about Stocktech Alerts