
CC BMI Calculator Security & Risk Analysis
wordpress.org/plugins/cc-bmi-calculatorAdd a free simple customizable BMI Calculator to your web site.
Is CC BMI Calculator Safe to Use in 2026?
Generally Safe
Score 98/100CC BMI Calculator has a strong security track record. Known vulnerabilities have been patched promptly.
The cc-bmi-calculator plugin v2.1.1 exhibits a mixed security posture. On the positive side, the code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. The absence of critical or high-severity taint flows is also a good indicator. However, there are significant areas of concern. A substantial 72% of output is not properly escaped, representing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the plugin has a history of two medium-severity CVEs, both related to XSS, with the most recent vulnerability recorded in May 2025, indicating a recurring pattern of input sanitization weaknesses. While no unpatched vulnerabilities are currently listed, the past issues combined with the output escaping shortcomings suggest a propensity for XSS flaws that may not have been fully addressed in the current version's sanitization practices. The presence of only one shortcode with no apparent capability checks or nonce checks, while not a large attack surface, becomes a potential entry point if the associated output is indeed vulnerable.
Key Concerns
- High percentage of unescaped output
- Two medium severity CVEs related to XSS
- Shortcode with no apparent capability checks
- Shortcode with no apparent nonce checks
CC BMI Calculator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CC BMI Calculator <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CC BMI Calculator <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
CC BMI Calculator Code Analysis
Output Escaping
CC BMI Calculator Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
CC BMI Calculator Maintenance & Trust
Maintenance Signals
Community Trust
CC BMI Calculator Alternatives
CC Canadian Mortgage Calculator
cc-canadian-mortgage-calculator
Add a free simple customizable Canadian mortgage calculator to your web site.
Disable Author Pages
disable-author-pages
Disable the author pages
Sidebar Shortcode
thinker-sidebar-shortcode
Add sidebars to WordPress posts and pages using shortcodes with a sidebar Name or ID.
WordPress Widgets Shortcode
wp-widgets-shortcode
Embed any widget area/dynamic sidebar to your pages/posts using the shortcode [dynamic-sidebar id='Your Widget Area/Sidebar name']
Shortcodes in Sidebar
shortcodes-in-sidebar
Shortcodes in Sidebar allows shortcodes to execute in sidebars.
CC BMI Calculator Developer Profile
7 plugins · 1K total installs
How We Detect CC BMI Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cc-bmi-calculator/cc-bmi-calculator.css/wp-content/plugins/cc-bmi-calculator/cc-bmi-calculator.js/wp-content/plugins/cc-bmi-calculator/cc-bmi-calculator.jscc-bmi-calculator.css?ver=cc-bmi-calculator.js?ver=HTML / DOM Fingerprints
cc-bmi-calculatorcc-color-fieldcc-bmi-calculator-wrapperid="cc-bmi-calculator-widget-title"id="cc-bmi-calculator-widget-input-height"id="cc-bmi-calculator-widget-input-weight"id="cc-bmi-calculator-widget-input-age"id="cc-bmi-calculator-widget-input-gender"id="cc-bmi-calculator-widget-input-unit-system"+4 morecc_bmi_calculator_ajax_object<div class="cc-bmi-calculator-wrapper"><div id="cc-bmi-calculator-calculator-area"><div id="cc-bmi-calculator-result-area">