WP Rouble Rate Security & Risk Analysis

wordpress.org/plugins/wp-rouble-rate

WP Rouble Rate - плагин для ежедневного обновления курса рубля ко всем доступным для ЦБР валютам.

10 active installs v1.0 PHP + WP 4.0+ Updated Mar 3, 2017
%d0%ba%d1%83%d1%80%d1%81-%d1%80%d1%83%d0%b1%d0%bb%d1%8fexchange-roublerouble-exchangingrouble-raterouble-rating
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Rouble Rate Safe to Use in 2026?

Generally Safe

Score 85/100

WP Rouble Rate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-rouble-rate" plugin, version 1.0, exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL injection vulnerabilities due to 100% prepared statements, and 100% properly escaped output are significant strengths. Furthermore, the lack of external HTTP requests and a clear vulnerability history, with zero recorded CVEs, contributes to a perception of low risk.

However, there are notable areas of concern. The plugin utilizes two cron events without any apparent authentication or capability checks, which could potentially be triggered maliciously if not properly secured. The presence of a file operation without further context also warrants caution, as it could be a vector for unauthorized file access or modification. The complete absence of nonce checks and capability checks across all identified entry points is a significant weakness, as it leaves the plugin open to various attacks, especially if any of its functionalities were to be exposed or leveraged.

In conclusion, while the plugin has avoided common pitfalls like raw SQL or unsanitized output, the lack of fundamental security checks like nonces and capability checks on its cron events represents a substantial risk. The attack surface is currently reported as zero unprotected entry points, but this could be a limitation of the analysis or a temporary state. Future versions should prioritize implementing robust authentication and authorization mechanisms.

Key Concerns

  • Cron events without auth checks
  • File operation without context
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

WP Rouble Rate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Rouble Rate Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WP Rouble Rate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0
Attack Surface

WP Rouble Rate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwprr_loader_exratewp-rouble-rate.php:21
actionwprr_loader_exrate__repeatwp-rouble-rate.php:22
actionadmin_bar_menuwp-rouble-rate.php:60

Scheduled Events 2

wprr_loader_exrate__repeat
wprr_loader_exrate
Maintenance & Trust

WP Rouble Rate Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedMar 3, 2017
PHP min version
Downloads998

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

WP Rouble Rate Alternatives

No alternatives data available yet.

Developer Profile

WP Rouble Rate Developer Profile

iTRON

9 plugins · 11K total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect WP Rouble Rate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Rouble Rate