Calculoid – Calculator builder Security & Risk Analysis

wordpress.org/plugins/calculoid-calculators-builder

Plugin makes it very easy to insert a calculator from Calculoid.com into your Wordpress website.

200 active installs v1.4 PHP + WP 3.9+ Updated Feb 17, 2020
buildercalculoidembedweb-formweb-calculator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Calculoid – Calculator builder Safe to Use in 2026?

Generally Safe

Score 85/100

Calculoid – Calculator builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "calculoid-calculators-builder" plugin version 1.4 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, which significantly mitigates risks of injection attacks and cross-site scripting. The presence of nonce and capability checks on its single identified entry point (a shortcode) further indicates a conscientious approach to securing user interactions.

However, the taint analysis reveals two flows with unsanitized paths. While these did not reach a critical or high severity in this analysis, they represent potential weaknesses that could be exploited in conjunction with other factors or if input validation is not robust enough at the point of entry. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a stable and well-maintained codebase over time. This history, combined with the strong static analysis signals, points to a plugin that is likely secure for most use cases. The key area for attention remains the identified taint flows, which warrant further investigation to ensure they do not present a latent risk.

In conclusion, "calculoid-calculators-builder" v1.4 is well-implemented from a security perspective, with many best practices followed. The vulnerability history is excellent. The only noted concern is the presence of two taint flows with unsanitized paths, which, while not currently critical, are the sole area that could potentially lead to a security issue if not carefully managed.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
None known

Calculoid – Calculator builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Calculoid – Calculator builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
9 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped9 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
render_admin_page (index.php:57)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Calculoid – Calculator builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[calculoid] index.php:26
WordPress Hooks 5
actionadmin_menuindex.php:25
filterbody_classindex.php:27
actionadmin_enqueue_scriptspost-meta-manager-api\index.php:42
actionadd_meta_boxespost-meta-manager-api\tmp\metabox.php:217
actionsave_postpost-meta-manager-api\tmp\metabox.php:245
Maintenance & Trust

Calculoid – Calculator builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 17, 2020
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Calculoid – Calculator builder Developer Profile

calculoid

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Calculoid – Calculator builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/calculoid-calculators-builder/post-meta-manager-api/libs/nestedSortable/style.css/wp-content/plugins/calculoid-calculators-builder/post-meta-manager-api/libs/pmm.js/wp-content/plugins/calculoid-calculators-builder/post-meta-manager-api/css/jquery-ui-1.10.4.custom.min.css/wp-content/plugins/calculoid-calculators-builder/post-meta-manager-api/libs/nestedSortable/jquery.nestable.js
Script Paths
https://embed.calculoid.com/scripts/combined.min.js

HTML / DOM Fingerprints

CSS Classes
calcShortcodeGeneratorFormcalcSubmitForm
HTML Comments
<!-- HTML --><!-- JS -->
Data Attributes
ng-controller="CalculoidMainCtrl"ng-init="init({calcId:apiKey:'showTitle:showDescription:ng-include="load()"+1 more
JS Globals
CalculoidMainCtrlcalculoid
Shortcode Output
[calculoid id="
FAQ

Frequently Asked Questions about Calculoid – Calculator builder