
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Security & Risk Analysis
wordpress.org/plugins/convertcalculatorEasily build calculators for your landing pages and web applications with Convert_'s intuitive calculator builder.
Is ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Safe to Use in 2026?
Generally Safe
Score 99/100ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators has a strong security track record. Known vulnerabilities have been patched promptly.
The convertcalculator plugin v2.0.7 presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having no observed dangerous functions, file operations, or external HTTP requests, significant concerns remain. The presence of an unprotected REST API route is a critical vulnerability, as it represents a direct entry point into the application that an attacker could exploit without authentication. The lack of nonce checks and capability checks across all entry points further exacerbates this risk, as it allows for potential unauthorized actions. Although the plugin has no currently unpatched CVEs, its history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one being recent, indicates a recurring weakness in input sanitization and output escaping, which is also reflected in the static analysis showing only 60% of outputs being properly escaped. This suggests a need for more robust sanitization and escaping mechanisms to prevent future XSS attacks.
Key Concerns
- Unprotected REST API route
- No nonce checks on entry points
- No capability checks on entry points
- 60% of outputs properly escaped
- History of medium XSS vulnerabilities
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ConvertCalculator for WordPress <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
ConvertCalculator for WordPress <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and type Parameter
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Code Analysis
Output Escaping
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Maintenance & Trust
Maintenance Signals
Community Trust
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Alternatives
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
AForms — Form Builder for Price Calculator & Cost Estimation
aforms-form-builder-for-price-calculator-cost-estimation
Form builder for Cost estimation and Custom order.
Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator
stylish-cost-calculator
Cost calculator for WordPress: 🌟 Engage visitors and boost conversions with interactive calculations, lead capture, and payment integrations.
Cost Calculator & Cost Estimation
cost-calculator-cost-estimation
Cost Calculator & Cost Estimation helps you to build any type of estimation forms on a few easy steps.
Project Cost Calculator
project-cost-calculator
Best Project Cost Calculator For WordPress Agencies ★★★★★ WordPress project cost calculator is a free plugin that displays an estimate of what your p …
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Developer Profile
1 plugin · 900 total installs
How We Detect ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertcalculator/build/index.js/wp-content/plugins/convertcalculator/build/index.csshttps://www.convertcalculator.com/scripts/embed.jsHTML / DOM Fingerprints
calculatorcalculator-framedata-calc-iddata-typeid="calculator-frame-sandbox="allow-same-origin allow-scripts allow-forms allow-popups allow-popups-to-escape-sandbox"/wp-json/wp/v2/block-render/convertcalculator/embedYou need to add an "id" to the "convertcalculator" shortcode. You can find the calculator id in the <a href="https://app.convertcalculator.com">editor</a>.<div>You need to add an "id" to the "convertcalculator_add_calculator" function.</div>