
Top Coin Security & Risk Analysis
wordpress.org/plugins/top-coinVirtual currency rankings wordpress plugin
Is Top Coin Safe to Use in 2026?
Generally Safe
Score 85/100Top Coin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'top-coin' plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a seemingly small attack surface with no recorded vulnerabilities or known CVEs. The absence of external HTTP requests and bundled libraries also reduces potential risks. However, significant concerns arise from the static analysis. The plugin lacks any nonce or capability checks, meaning that even though there are no unprotected entry points identified, any action triggered by its single shortcode is essentially unauthenticated and unprivileged, posing a risk for unauthorized actions if the shortcode functionality allows for it.
Furthermore, the presence of the `create_function` dangerous function is a critical red flag, as it can be exploited for remote code execution if user-supplied data influences its execution. The most concerning finding is that 100% of the output from the plugin is not properly escaped. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through the plugin's output, impacting users who interact with those outputs. Given the lack of vulnerability history, it's difficult to ascertain if these issues have been exploited previously, but the current state of the code presents clear and present dangers.
Key Concerns
- Dangerous function create_function used
- All output unescaped (XSS risk)
- No nonce checks
- No capability checks
Top Coin Security Vulnerabilities
Top Coin Code Analysis
Dangerous Functions Found
Output Escaping
Top Coin Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Top Coin Maintenance & Trust
Maintenance Signals
Community Trust
Top Coin Alternatives
Bitcart for WooCommerce
bitcartcc-for-woocommerce
Bitcart is a free and open-source cryptocurrency payment processor which allows you to receive cryptocurrency payments directly, with no fees, transac …
Bitcoin Payments for WP WooCommerce
bitcoin-payments-for-wp-woocommerce
Bitcoin Payments for WooCommerce is a Wordpress plugin that allows to accept bitcoins at WooCommerce-powered online stores.
Easy Coin Table
easy-coin-table
Virtual currency rankings wordpress plugin
Top Coin Developer Profile
6 plugins · 100 total installs
How We Detect Top Coin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/top-coin/css/bhk_style.cssHTML / DOM Fingerprints
bhk-content-coinbhk-table-coinwp-heading-inlineinfo-pluginid="col-container"class="wp-clearfix"id="col-left"id="col-right"[topcoin num="5"][topcoin num="10"]