
StockViz Security & Risk Analysis
wordpress.org/plugins/stockvizThe Wordpress shortcode plugin allows you to pull in the latest stock price from within your post.
Is StockViz Safe to Use in 2026?
Generally Safe
Score 85/100StockViz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The stockviz v1.0.1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and has no recorded vulnerability history, which suggests a potentially stable codebase. Furthermore, the attack surface is minimal, with only one shortcode and no apparent unprotected entry points like AJAX handlers or REST API routes. However, significant concerns arise from the static analysis. The presence of the `create_function` is a notable risk, as it can be a vector for code injection if not handled with extreme caution and proper sanitization. Critically, none of the plugin's outputs are properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks further amplifies these risks, as it implies that actions triggered by the shortcode or other potential entry points might not be adequately protected against unauthorized execution.
Key Concerns
- Unescaped output
- Dangerous function usage (create_function)
- Missing nonce checks
- Missing capability checks
StockViz Security Vulnerabilities
StockViz Release Timeline
StockViz Code Analysis
Dangerous Functions Found
Output Escaping
StockViz Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
StockViz Maintenance & Trust
Maintenance Signals
Community Trust
StockViz Alternatives
Adanos Market Sentiment Widgets
adanos-market-sentiment-widgets
Embed self-hosted stock sentiment widgets and shortcodes for WordPress, powered by Adanos.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Razorpay for WooCommerce
woo-razorpay
Start accepting payments in minutes with 100% digital onboarding & feature filled Razorpay payment gateway with the WooCommerce plugin.
StockViz Developer Profile
1 plugin · 10 total installs
How We Detect StockViz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<span style="font-size:.*?;font-family:.*?;height:20px;padding-left:5px;padding-right:5px;background-color:.*?;display:inline-block;border-radius:3px 3px 3px 3px;-moz-border-radius: 3px;-webkit-border-radius: 3px;"><a style="text-decoration:none;" href="http://stockviz.biz/StockDive.aspx?TICKER=.*?" title=".*?">.*?</a> .*? <span style="color:.*?">.*? .*?</span></span>