
BMI / IMC Calculator Security & Risk Analysis
wordpress.org/plugins/bmi-imc-calculatorA simple calculator to show your users BMI (Body Mass Index)
Is BMI / IMC Calculator Safe to Use in 2026?
Generally Safe
Score 85/100BMI / IMC Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The BMI IMC Calculator plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. The fact that all SQL queries are prepared statements is a significant strength, preventing SQL injection vulnerabilities. Additionally, the plugin has no known CVEs, suggesting a history of secure development or prompt patching.
However, there are some notable concerns. The low percentage of properly escaped output (18%) presents a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly as the plugin has one shortcode which acts as an entry point. The lack of nonce and capability checks on its single shortcode is another significant vulnerability, as it allows any logged-in user to trigger the shortcode's functionality without proper authorization or validation, potentially leading to unintended actions or data manipulation.
In conclusion, while the plugin avoids several common and severe vulnerability types, the insufficient output escaping and the complete absence of authorization checks on its shortcode introduce tangible risks. These weaknesses, if exploited, could lead to XSS attacks or unauthorized actions. Addressing these specific areas would significantly improve the plugin's overall security.
Key Concerns
- Unescaped output detected
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
BMI / IMC Calculator Security Vulnerabilities
BMI / IMC Calculator Code Analysis
Output Escaping
BMI / IMC Calculator Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
BMI / IMC Calculator Maintenance & Trust
Maintenance Signals
Community Trust
BMI / IMC Calculator Alternatives
FitCalc – BMI Calculator
fitcalc-bmi-calculator
Lightweight BMI calculator with Metric and Imperial units. Use the shortcode [fitcalc_bmi].
BMI Calculator
bmi-calculator
This BMI calculator can give out the BMI value as well as basic understandings based on age, height, and weight.
Responsive BMI Calculator
responsive-bmi-calculator
A BMI (Body Mass Index) calculator, free, responsive and easy to use. The user receives his BMI and medical advices according to the World Health Orga …
Simple BMI Form
simple-bmi-form
BMI calculator form. The visitor may select Imperial, US or Metric units.
Human BMI Calculator
human-bmi-calculator
Human BMI (Body Mass Index) Calculator will help you to check your current BMI for your height and weight.
BMI / IMC Calculator Developer Profile
1 plugin · 100 total installs
How We Detect BMI / IMC Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bmi-imc-calculator/includes/css/style.css/wp-content/plugins/bmi-imc-calculator/includes/css/table.css/wp-content/plugins/bmi-imc-calculator/includes/css/fontello.css/wp-content/plugins/bmi-imc-calculator/includes/js/jquery.maskMoney.js/wp-content/plugins/bmi-imc-calculator/includes/js/imc.js/wp-content/plugins/bmi-imc-calculator/includes/images/header_background_1.png/wp-content/plugins/bmi-imc-calculator/includes/js/jquery.maskMoney.js/wp-content/plugins/bmi-imc-calculator/includes/js/imc.jsbmi-imc-calculator/includes/css/fontello.css?ver=bmi-imc-calculator/includes/js/jquery.maskMoney.js?ver=bmi-imc-calculator/includes/js/imc.js?ver=HTML / DOM Fingerprints
TituloSeccionicon-gaugeicon-text-heightcalcularIMCSuIMCresultado_imcrojo+4 more<!-- STYLES Y SCRIPTS --><!-- ARCHIVOS DE TRADUCCION --><!-- FUNCION QUE MUESTRA LA CALCULADORA --><!-- SHORTCODE -->+1 moreid="CalculoIMC"name="sistema_metrico"id="sistema_metrico"name="peso"id="peso"name="altura"+8 moreESW_PLUGIN_URLESW_VERSION_NUM<div class="TituloSeccion" id="SeccionIMC"><table id="Tabla_IMC">