Campaign ROI Calculator v1.0 Security & Risk Analysis

wordpress.org/plugins/campaign-roi-return-on-investment-calculator-v10

Campaign ROI Calculator is a simple to use calculator that calculates how much money you might make given your budget, and popular online marketing ma …

10 active installs v1.0 PHP + WP 2.8+ Updated Unknown
campaignppcreturn-on-investmentroisem
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Campaign ROI Calculator v1.0 Safe to Use in 2026?

Generally Safe

Score 100/100

Campaign ROI Calculator v1.0 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "campaign-roi-return-on-investment-calculator-v10" v1.0 exhibits a generally good security posture based on the provided static analysis. There are no detected AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the code signals indicate no dangerous functions used, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, all of which are strong security indicators.

However, a significant concern arises from the low percentage of properly escaped output. With 27% of outputs properly escaped out of 37 total, this suggests that a substantial portion of user-facing data might be vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks and capability checks is also concerning, as these are fundamental security mechanisms for preventing unauthorized actions and ensuring data integrity, especially if any interaction points were to be introduced in the future.

The plugin's vulnerability history is clean, with zero known CVEs. This indicates a historical lack of exploited vulnerabilities, which is positive. However, the absence of vulnerabilities in the past does not guarantee future security, especially in light of the identified output escaping issues. The overall conclusion is that while the plugin avoids common pitfalls like raw SQL and large attack surfaces, the prevalent lack of output escaping presents a notable risk of XSS vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Campaign ROI Calculator v1.0 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Campaign ROI Calculator v1.0 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped37 total outputs
Attack Surface

Campaign ROI Calculator v1.0 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initaffilicore-wp-ppc-media-roi-calculator.php:13
Maintenance & Trust

Campaign ROI Calculator v1.0 Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Campaign ROI Calculator v1.0 Developer Profile

YoavShalev

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Campaign ROI Calculator v1.0

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/campaign-roi-return-on-investment-calculator-v10/js/organictabs.jquery.js/wp-content/plugins/campaign-roi-return-on-investment-calculator-v10/js/vtip.js/wp-content/plugins/campaign-roi-return-on-investment-calculator-v10/css/style.css
Script Paths
/wp-content/plugins/campaign-roi-return-on-investment-calculator-v10/js/organictabs.jquery.js/wp-content/plugins/campaign-roi-return-on-investment-calculator-v10/js/vtip.js
Version Parameters
campaign-roi-return-on-investment-calculator-v10/js/organictabs.jquery.js?ver=campaign-roi-return-on-investment-calculator-v10/js/vtip.js?ver=campaign-roi-return-on-investment-calculator-v10/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
affilicore_wp_ppc_media_roi_calculator_class
Data Attributes
id='_colorpicker_border_ppc'id='_colorpicker_ppc'id='_colorpicker_text_ppc'id='_color_border_ppc'id='_color_ppc'id='_color_text_ppc'+6 more
JS Globals
affilicore_wp_ppc_media_roi_calculator_urlshowresult_affilicore_wp_ppc_media_roi_calculator_for_ppc
FAQ

Frequently Asked Questions about Campaign ROI Calculator v1.0