CC Canadian Mortgage Calculator Security & Risk Analysis

wordpress.org/plugins/cc-canadian-mortgage-calculator

Add a free simple customizable Canadian mortgage calculator to your web site.

100 active installs v2.1.1 PHP + WP 3.0+ Updated Nov 14, 2025
canadamortgage-calculatorshortcodesidebarwidget
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is CC Canadian Mortgage Calculator Safe to Use in 2026?

Generally Safe

Score 99/100

CC Canadian Mortgage Calculator has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2025Updated 4mo ago
Risk Assessment

The "cc-canadian-mortgage-calculator" plugin v2.1.1 exhibits a mixed security posture. While the static analysis shows no dangerous functions, raw SQL queries, or external HTTP requests, and the fact that there are no unpatched CVEs is positive, significant concerns remain. A notable weakness is the low rate of proper output escaping (32%), which indicates a high potential for Cross-Site Scripting (XSS) vulnerabilities, a pattern corroborated by its vulnerability history which lists a past medium severity XSS. The plugin also lacks nonce and capability checks, and its single shortcode represents an entry point without any authorization checks, further increasing the risk of unauthorized access or execution of actions. The absence of taint analysis flows, while seemingly positive, could also suggest a lack of comprehensive security testing or a very limited code complexity, rather than a truly secure implementation. Overall, the plugin has some good practices regarding database interaction and external communication, but the significant lack of output sanitization and authorization checks on its entry points presents a substantial risk.

Key Concerns

  • Low output escaping rate
  • Missing capability checks
  • Missing nonce checks
  • Shortcode without auth check
  • Past medium CVE (XSS)
Vulnerabilities
1

CC Canadian Mortgage Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11383medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CC Canadian Mortgage Calculator <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 6, 2025 Patched in 2.1.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

CC Canadian Mortgage Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

32% escaped69 total outputs
Attack Surface

CC Canadian Mortgage Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cc-mortgage-canada] cc-mortgage-canada.php:174
WordPress Hooks 3
actionwidgets_initcc-mortgage-canada.php:141
actionwp_enqueue_scriptscc-mortgage-canada.php:152
actionadmin_enqueue_scriptscc-mortgage-canada.php:161
Maintenance & Trust

CC Canadian Mortgage Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 14, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

CC Canadian Mortgage Calculator Developer Profile

CC

7 plugins · 1K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect CC Canadian Mortgage Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cc-canadian-mortgage-calculator/cc-mortgage-canada.css/wp-content/plugins/cc-canadian-mortgage-calculator/cc-mortgage-canada.js
Script Paths
/wp-content/plugins/cc-canadian-mortgage-calculator/cc-mortgage-canada.js/wp-content/plugins/cc-canadian-mortgage-calculator/cc-mortgage-canada-admin.js
Version Parameters
cc-mortgage-canada.css?ver=2.1.1cc-mortgage-canada.js?ver=2.1.1

HTML / DOM Fingerprints

CSS Classes
cc-color-field
Data Attributes
data-iddata-currency_symboldata-dev_creditdata-bg_colordata-border_colordata-text_color
JS Globals
jQuery$J
FAQ

Frequently Asked Questions about CC Canadian Mortgage Calculator