Cost Calculator for Elementor Security & Risk Analysis

wordpress.org/plugins/cost-calculator-for-elementor

With Cost Calculator for Elementor you can create forms with dynamically calculated fields to display the calculated values!

500 active installs v1.4.0 PHP 5.2+ WP 2.0+ Updated Nov 28, 2025
calculatorcalculator-formcost-calculatorelementorelementor-forms
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Cost Calculator for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Cost Calculator for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2025Updated 4mo ago
Risk Assessment

The "cost-calculator-for-elementor" plugin v1.4.0 demonstrates good security practices in several key areas. The static analysis shows a well-contained attack surface with only one AJAX handler, and importantly, no unauthenticated entry points. All SQL queries are properly prepared, and all output is correctly escaped, indicating a strong defense against common injection and cross-site scripting (XSS) vulnerabilities stemming from direct code execution or rendering. The absence of file operations and the limited number of external HTTP requests also suggest a reduced risk of unauthorized file manipulation or data exfiltration through insecure external communications.

However, there are notable areas for improvement. The plugin exhibits a complete lack of capability checks for its single AJAX handler, meaning any authenticated user, regardless of their role or permissions, can trigger this functionality. This is a significant concern as it could lead to privilege escalation or unauthorized actions if the handler itself performs sensitive operations. While the plugin has a history of one medium-severity CVE for XSS, and it is currently patched, this past vulnerability combined with the missing capability checks for the AJAX handler warrants attention. The presence of external HTTP requests, while only two, also introduces a potential attack vector that should be carefully monitored.

In conclusion, the plugin has a solid foundation with robust input sanitization and SQL preparation. The primary weakness lies in the insufficient authorization checks for its AJAX endpoint. Addressing this oversight is crucial to prevent potential abuse by authenticated users. While the past CVE is resolved, the general principle of comprehensive capability checks for all sensitive endpoints should be a priority for future development to maintain a strong security posture.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
1

Cost Calculator for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47476medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cost Calculator for Elementor <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 1.3.4 (7d)
Code Analysis
Analyzed Mar 16, 2026

Cost Calculator for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
75 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped75 total outputs
Attack Surface

Cost Calculator for Elementor Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 16
actionelementor/frontend/after_register_scriptscost-calculator-for-elementor.php:20
actionelementor/editor/before_enqueue_scriptscost-calculator-for-elementor.php:21
actionelementor/widgets/registercost-calculator-for-elementor.php:22
actionelementor_pro/initcost-calculator-for-elementor.php:23
actionwp_footerfields\number_formats.php:18
actionelementor/preview/initfields\number_formats.php:22
actionelementor/preview/initfields\total.php:19
actionwp_footerfields\total.php:22
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
Maintenance & Trust

Cost Calculator for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version5.2
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Cost Calculator for Elementor Developer Profile

add-ons.org

55 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
50 days
View full developer profile
Detection Fingerprints

How We Detect Cost Calculator for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cost-calculator-for-elementor/libs/tribute/tribute.css/wp-content/plugins/cost-calculator-for-elementor/libs/tribute/tribute.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator_editor.js/wp-content/plugins/cost-calculator-for-elementor/libs/formula_evaluator-min.js/wp-content/plugins/cost-calculator-for-elementor/libs/autoNumeric-1.9.45.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator.css
Script Paths
libs/tribute/tribute.jslibs/calculator_editor.jslibs/formula_evaluator-min.jslibs/autoNumeric-1.9.45.jslibs/calculator.js
Version Parameters
elementor-calculator/libs/calculator.css?ver=elementor-calculator/libs/calculator_editor.js?ver=elementor-calculator/libs/calculator.js?ver=elementor-calculator/libs/formula_evaluator-min.js?ver=elementor-calculator/libs/autoNumeric-1.9.45.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-calculator-form
Data Attributes
data-elementor-calculator-iddata-elementor-calculator-fields
JS Globals
elementor_calculator
Shortcode Output
[cost_calculator
FAQ

Frequently Asked Questions about Cost Calculator for Elementor