
ZPT Metals Security & Risk Analysis
wordpress.org/plugins/zpt-metalsA solution provided to display precious Metals(Gold, Silver, Platinum and 36+ metals) rates in the desired currencies (USD,GBP, CAD etc).
Is ZPT Metals Safe to Use in 2026?
Generally Safe
Score 85/100ZPT Metals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zpt-metals plugin v1.2.1 exhibits a generally good security posture based on the static analysis. It demonstrates excellent practices by having no known critical or high severity taint flows and 100% of its SQL queries utilizing prepared statements, which significantly mitigates the risk of SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to a positive security outlook, suggesting the developers are either diligent in patching or have not historically introduced significant flaws. However, there are areas that warrant attention. The plugin has a notable percentage of improperly escaped output (43%), which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is displayed without proper sanitization. Additionally, the presence of 5 external HTTP requests, while not inherently problematic, could introduce risks if not handled securely, such as validating responses or using robust libraries. The lack of capability checks on any entry points is a concern, meaning any authenticated user could potentially trigger functionality that might have unintended consequences or expose sensitive information if other security measures fail. While the overall picture is positive due to strong SQL practices and no known exploits, the unescaped output and the absence of capability checks represent potential avenues for attack that should be addressed.
Key Concerns
- Significant portion of output not properly escaped
- No capability checks on entry points
- External HTTP requests present
ZPT Metals Security Vulnerabilities
ZPT Metals Code Analysis
Output Escaping
Data Flow Analysis
ZPT Metals Attack Surface
Shortcodes 1
WordPress Hooks 9
Scheduled Events 20
Maintenance & Trust
ZPT Metals Maintenance & Trust
Maintenance Signals
Community Trust
ZPT Metals Developer Profile
1 plugin · 60 total installs
How We Detect ZPT Metals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zpt-metals/assets/css/zpt-metals-frontend.css/wp-content/plugins/zpt-metals/assets/js/zpt-metals-frontend.js/wp-content/plugins/zpt-metals/assets/js/zpt-metals-frontend.jszpt-metals/assets/css/zpt-metals-frontend.css?ver=zpt-metals/assets/js/zpt-metals-frontend.js?ver=HTML / DOM Fingerprints
Display output of shortcode with provided attributesatts can be an array with following attributesEndpoint for get rates in CaratRespect API request limits. So serve database saved results until database+5 moretypecurrencysymbolsbasedate-formatprice-round+3 more[zpt-metals]