
CC Quebec Income Tax Calculator Security & Risk Analysis
wordpress.org/plugins/cc-quebec-tax-calculatorAdd a free simple customizable Quebec income tax calculator to your web site.
Is CC Quebec Income Tax Calculator Safe to Use in 2026?
Generally Safe
Score 100/100CC Quebec Income Tax Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cc-quebec-tax-calculator" plugin, in version 0.2024.1, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs. The static analysis also shows no dangerous functions, file operations, or external HTTP requests, and the attack surface is relatively small with only one shortcode and no unprotected entry points. This suggests a development team that is aware of some security fundamentals.
However, there are significant concerns stemming from the output escaping and nonce/capability checks. A mere 25% of outputs are properly escaped, which is a substantial weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-provided data is displayed without adequate sanitization, especially given the lack of any recorded nonce or capability checks. The absence of these checks means that even if the shortcode's functionality is limited, any user, authenticated or not (depending on how shortcodes are rendered), could potentially trigger its execution, and improperly escaped output could then be exploited.
The complete lack of taint analysis results is also notable, though it could indicate a lack of complex data flows or that the analysis tools did not identify any. Combined with the low percentage of escaped output and zero capability/nonce checks, the overall risk leans towards potential XSS vulnerabilities, which can have serious security implications for websites. While the plugin has a clean vulnerability history, the identified code signals point to a real and present risk that needs to be addressed.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
CC Quebec Income Tax Calculator Security Vulnerabilities
CC Quebec Income Tax Calculator Code Analysis
Output Escaping
CC Quebec Income Tax Calculator Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
CC Quebec Income Tax Calculator Maintenance & Trust
Maintenance Signals
Community Trust
CC Quebec Income Tax Calculator Alternatives
CC Ontario Income Tax Calculator
cc-ontario-tax-calculator
Add a free simple customizable Ontario income tax calculator to your web site.
CC Canadian Mortgage Calculator
cc-canadian-mortgage-calculator
Add a free simple customizable Canadian mortgage calculator to your web site.
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
Calculator
calculator
Adds a widget that display a simple calculator.
CC Mortgage Calculator
cc-mortgage-calculator
Add a free simple customizable mortgage calculator to your web site.
CC Quebec Income Tax Calculator Developer Profile
7 plugins · 1K total installs
How We Detect CC Quebec Income Tax Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc.css/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc.js/wp-content/plugins/cc-quebec-tax-calculator/cc-income-tax-qc-admin.jscc-income-tax-qc.css?ver=0.2024.1cc-income-tax-qc.js?ver=0.2024.1HTML / DOM Fingerprints
cc-color-fieldid='cc_income_tax_qc_shortcode-colors'id='cc_income_tax_qc-colors'var $J = jQuery.noConflict();<a href="https://calculatorscanada.ca/quebec-income-tax-calculator/" target="_blank">