
Cost Calculator for Elementor Security & Risk Analysis
wordpress.org/plugins/cost-calculator-for-elementorWith Cost Calculator for Elementor you can create forms with dynamically calculated fields to display the calculated values!
Is Cost Calculator for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Cost Calculator for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "cost-calculator-for-elementor" plugin v1.4.0 demonstrates good security practices in several key areas. The static analysis shows a well-contained attack surface with only one AJAX handler, and importantly, no unauthenticated entry points. All SQL queries are properly prepared, and all output is correctly escaped, indicating a strong defense against common injection and cross-site scripting (XSS) vulnerabilities stemming from direct code execution or rendering. The absence of file operations and the limited number of external HTTP requests also suggest a reduced risk of unauthorized file manipulation or data exfiltration through insecure external communications.
However, there are notable areas for improvement. The plugin exhibits a complete lack of capability checks for its single AJAX handler, meaning any authenticated user, regardless of their role or permissions, can trigger this functionality. This is a significant concern as it could lead to privilege escalation or unauthorized actions if the handler itself performs sensitive operations. While the plugin has a history of one medium-severity CVE for XSS, and it is currently patched, this past vulnerability combined with the missing capability checks for the AJAX handler warrants attention. The presence of external HTTP requests, while only two, also introduces a potential attack vector that should be carefully monitored.
In conclusion, the plugin has a solid foundation with robust input sanitization and SQL preparation. The primary weakness lies in the insufficient authorization checks for its AJAX endpoint. Addressing this oversight is crucial to prevent potential abuse by authenticated users. While the past CVE is resolved, the general principle of comprehensive capability checks for all sensitive endpoints should be a priority for future development to maintain a strong security posture.
Key Concerns
- Missing capability checks on AJAX handler
Cost Calculator for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cost Calculator for Elementor <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Cost Calculator for Elementor Code Analysis
Output Escaping
Cost Calculator for Elementor Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
Cost Calculator for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Cost Calculator for Elementor Alternatives
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Cost Calculator for Contact Form 7 – Price Calculator Free
cf7-cost-calculator-price-calculation
With Contact Form 7 Cost Calculator – Price Calculation Form you can create forms with dynamically calculated fields to display the calculated values!
Cost Calculator for WPForms
cost-calculator-for-wpforms
With Cost Calculator for WPForms you can create forms with dynamically calculated fields to display the calculated values!
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Calculated Fields Form
calculated-fields-form
The CFF plugin allows you to create both simple and professional forms. Its form builder includes dynamic calculated fields and many other controls.
Cost Calculator for Elementor Developer Profile
55 plugins · 26K total installs
How We Detect Cost Calculator for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cost-calculator-for-elementor/libs/tribute/tribute.css/wp-content/plugins/cost-calculator-for-elementor/libs/tribute/tribute.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator_editor.js/wp-content/plugins/cost-calculator-for-elementor/libs/formula_evaluator-min.js/wp-content/plugins/cost-calculator-for-elementor/libs/autoNumeric-1.9.45.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator.js/wp-content/plugins/cost-calculator-for-elementor/libs/calculator.csslibs/tribute/tribute.jslibs/calculator_editor.jslibs/formula_evaluator-min.jslibs/autoNumeric-1.9.45.jslibs/calculator.jselementor-calculator/libs/calculator.css?ver=elementor-calculator/libs/calculator_editor.js?ver=elementor-calculator/libs/calculator.js?ver=elementor-calculator/libs/formula_evaluator-min.js?ver=elementor-calculator/libs/autoNumeric-1.9.45.js?ver=HTML / DOM Fingerprints
elementor-calculator-formdata-elementor-calculator-iddata-elementor-calculator-fieldselementor_calculator[cost_calculator