CC Quebec Income Tax Calculator Security & Risk Analysis

wordpress.org/plugins/cc-quebec-tax-calculator

Add a free simple customizable Quebec income tax calculator to your web site.

10 active installs v0.2024.1 PHP + WP 3.0+ Updated Nov 14, 2025
calculatorcanadaincome-tax-calculatorquebecsidebar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CC Quebec Income Tax Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

CC Quebec Income Tax Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "cc-quebec-tax-calculator" plugin, in version 0.2024.1, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs. The static analysis also shows no dangerous functions, file operations, or external HTTP requests, and the attack surface is relatively small with only one shortcode and no unprotected entry points. This suggests a development team that is aware of some security fundamentals.

However, there are significant concerns stemming from the output escaping and nonce/capability checks. A mere 25% of outputs are properly escaped, which is a substantial weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-provided data is displayed without adequate sanitization, especially given the lack of any recorded nonce or capability checks. The absence of these checks means that even if the shortcode's functionality is limited, any user, authenticated or not (depending on how shortcodes are rendered), could potentially trigger its execution, and improperly escaped output could then be exploited.

The complete lack of taint analysis results is also notable, though it could indicate a lack of complex data flows or that the analysis tools did not identify any. Combined with the low percentage of escaped output and zero capability/nonce checks, the overall risk leans towards potential XSS vulnerabilities, which can have serious security implications for websites. While the plugin has a clean vulnerability history, the identified code signals point to a real and present risk that needs to be addressed.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

CC Quebec Income Tax Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CC Quebec Income Tax Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped63 total outputs
Attack Surface

CC Quebec Income Tax Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cc_income_tax_qc] cc-income-tax-qc.php:174
WordPress Hooks 3
actionwidgets_initcc-income-tax-qc.php:132
actionwp_enqueue_scriptscc-income-tax-qc.php:142
actionadmin_enqueue_scriptscc-income-tax-qc.php:151
Maintenance & Trust

CC Quebec Income Tax Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 14, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CC Quebec Income Tax Calculator Developer Profile

CC

7 plugins · 1K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect CC Quebec Income Tax Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc.css/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc.js/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc-admin.js
Version Parameters
cc-income-tax-qc.css?ver=0.2024.1cc-income-tax-qc.js?ver=0.2024.1

HTML / DOM Fingerprints

CSS Classes
cc-color-field
Data Attributes
id='cc_income_tax_qc_shortcode-colors'id='cc_income_tax_qc-colors'
JS Globals
var $J = jQuery.noConflict();
Shortcode Output
<a href="https://calculatorscanada.ca/quebec-income-tax-calculator/" target="_blank">
FAQ

Frequently Asked Questions about CC Quebec Income Tax Calculator