
CalcFusion for WP Security & Risk Analysis
wordpress.org/plugins/calcfusion-for-wpCalcFusion brings flexibility by utilizing Excel computations and functions as a backend system to your existing WordPress site.
Is CalcFusion for WP Safe to Use in 2026?
Generally Safe
Score 85/100CalcFusion for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Calcfusion for WP plugin v1.1.3 exhibits a concerning security posture due to its unprotected AJAX handlers. While the plugin demonstrates good practices in handling SQL queries with prepared statements and avoids dangerous functions and file operations, the lack of authentication checks on all identified AJAX entry points creates a significant attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended behavior or further exploitation if vulnerabilities are present within them.
The taint analysis, while limited in scope, did identify flows with unsanitized paths. Although no critical or high severity issues were flagged in the taint analysis, these unsanitized paths are a red flag for potential injection vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive. However, this does not negate the risks posed by the static analysis findings, particularly the unprotected AJAX endpoints and the potential for issues stemming from unsanitized paths.
In conclusion, the plugin has strengths in its SQL handling and absence of certain dangerous code patterns. Nevertheless, the identified unprotected AJAX handlers and unsanitized paths represent critical weaknesses that require immediate attention. A robust security strategy would involve implementing proper authentication and authorization checks for all AJAX endpoints and thoroughly sanitizing all user-supplied input to mitigate potential injection risks.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Lack of nonce checks on AJAX
- Insufficient output escaping
- Bundled Guzzle library
CalcFusion for WP Security Vulnerabilities
CalcFusion for WP Release Timeline
CalcFusion for WP Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
CalcFusion for WP Attack Surface
AJAX Handlers 5
WordPress Hooks 4
Maintenance & Trust
CalcFusion for WP Maintenance & Trust
Maintenance Signals
Community Trust
CalcFusion for WP Alternatives
No alternatives data available yet.
CalcFusion for WP Developer Profile
1 plugin · 10 total installs
How We Detect CalcFusion for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calcfusion-for-wp/css/calcfusion-for-wp.css/wp-content/plugins/calcfusion-for-wp/js/calcfusion-for-wp.js/wp-content/plugins/calcfusion-for-wp/js/calcfusion-for-wp.jscalcfusion-for-wp/style.css?ver=calcfusion-for-wp/script.js?ver=HTML / DOM Fingerprints
calcfusion_wp_ajax_urlCalcFusionClient/wp-json/calcfusion/v1/settings[calcfusion_calculator]