ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Security & Risk Analysis

wordpress.org/plugins/convertcalculator

Easily build calculators for your landing pages and web applications with Convert_'s intuitive calculator builder.

900 active installs v2.0.7 PHP 7.2+ WP 6.6+ Updated Jun 13, 2025
cost-calculatorcost-estimationprice-calculatorproduct-configuratorquote-form
99
A · Safe
CVEs total2
Unpatched0
Last CVEDec 30, 2024
Download
Safety Verdict

Is ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Safe to Use in 2026?

Generally Safe

Score 99/100

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 30, 2024Updated 9mo ago
Risk Assessment

The convertcalculator plugin v2.0.7 presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having no observed dangerous functions, file operations, or external HTTP requests, significant concerns remain. The presence of an unprotected REST API route is a critical vulnerability, as it represents a direct entry point into the application that an attacker could exploit without authentication. The lack of nonce checks and capability checks across all entry points further exacerbates this risk, as it allows for potential unauthorized actions. Although the plugin has no currently unpatched CVEs, its history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one being recent, indicates a recurring weakness in input sanitization and output escaping, which is also reflected in the static analysis showing only 60% of outputs being properly escaped. This suggests a need for more robust sanitization and escaping mechanisms to prevent future XSS attacks.

Key Concerns

  • Unprotected REST API route
  • No nonce checks on entry points
  • No capability checks on entry points
  • 60% of outputs properly escaped
  • History of medium XSS vulnerabilities
Vulnerabilities
2

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-56302medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ConvertCalculator for WordPress <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 30, 2024 Patched in 1.1.2 (10d)
CVE-2024-10015medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ConvertCalculator for WordPress <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and type Parameter

Nov 15, 2024 Patched in 1.1.2 (5d)
Code Analysis
Analyzed Mar 16, 2026

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Attack Surface
1 unprotected

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Attack Surface

Entry Points2
Unprotected1

REST API Routes 1

POST/wp-json/wp/v2/block-render/convertcalculator/embedconvertcalculator.php:61

Shortcodes 1

[convertcalculator] convertcalculator.php:100
WordPress Hooks 4
actionwp_headconvertcalculator.php:31
actioninitconvertcalculator.php:55
actionrest_api_initconvertcalculator.php:60
actionelementor/widgets/registerconvertcalculator.php:200
Maintenance & Trust

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJun 13, 2025
PHP min version7.2
Downloads15K

Community Trust

Rating100/100
Number of ratings1
Active installs900
Developer Profile

ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators Developer Profile

jorisderuiter

1 plugin · 900 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convertcalculator/build/index.js/wp-content/plugins/convertcalculator/build/index.css
Script Paths
https://www.convertcalculator.com/scripts/embed.js

HTML / DOM Fingerprints

CSS Classes
calculatorcalculator-frame
Data Attributes
data-calc-iddata-typeid="calculator-frame-sandbox="allow-same-origin allow-scripts allow-forms allow-popups allow-popups-to-escape-sandbox"
REST Endpoints
/wp-json/wp/v2/block-render/convertcalculator/embed
Shortcode Output
You need to add an "id" to the "convertcalculator" shortcode. You can find the calculator id in the <a href="https://app.convertcalculator.com">editor</a>.<div>You need to add an "id" to the "convertcalculator_add_calculator" function.</div>
FAQ

Frequently Asked Questions about ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators