
Devinlabs Unit Conventer Security & Risk Analysis
wordpress.org/plugins/devinlabs-length-and-distance-converterThis Widget is use for calculate the length and distance conversions. in form of centimeter, foot, inch, kilometer, meter, mile, millimeter, yard
Is Devinlabs Unit Conventer Safe to Use in 2026?
Generally Safe
Score 85/100Devinlabs Unit Conventer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "devinlabs-length-and-distance-converter" plugin v1.0.0 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive. The code utilizes prepared statements for all SQL queries, which is a critical security best practice. The plugin also performs a capability check, indicating some level of access control is considered.
However, there are areas for improvement. The primary concern lies with the output escaping, where only 40% of the outputs are properly escaped. This leaves a significant portion of user-facing data potentially vulnerable to Cross-Site Scripting (XSS) attacks if the input is not adequately sanitized before being displayed. The lack of nonce checks, while not directly tied to an AJAX entry point in this analysis, could be a concern if the shortcode were to interact with backend functionalities in a way that could be exploited.
The plugin's vulnerability history is completely clean, with no recorded CVEs. This suggests a track record of security awareness or simply a lack of past vulnerabilities being discovered. While this is positive, it doesn't negate the potential risks identified in the static analysis, particularly concerning output escaping. Overall, the plugin has a solid foundation but requires attention to output sanitization to mitigate potential XSS risks.
Key Concerns
- Poor output escaping (only 40% properly escaped)
- No nonce checks present
Devinlabs Unit Conventer Security Vulnerabilities
Devinlabs Unit Conventer Code Analysis
Output Escaping
Devinlabs Unit Conventer Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Devinlabs Unit Conventer Maintenance & Trust
Maintenance Signals
Community Trust
Devinlabs Unit Conventer Alternatives
Metric Converter
metric-converter
Metric Converter is a WP extension for the visual editor that allows to convert metric units to American linear measures (inch, oz, lbs).
Unit Converter Pro
unit-converter-pro
This widget can be added anywhere in your site and provides a fully featured unit converter that can be used in various configurations.
w2pe Measurement Widget
w2pe-measurement-widget
w2pe Measurement Widget is especially designed to make your units conversion job a whole lot easier. Here you'll find instant conversions for tho …
WP Unit Converter
wp-unit-converter
WP Unit Converter allows you to convert Length/Distance, Temperature, Time, Weight, Area and Speed metrics in different units of measurement.
Smart Convert – Currency & Unit Conversion
smart-convert-currency-unit-conversion
The ultimate conversion engine: 153 Currencies, 105+ Units, Custom Unit Builder, GeoIP detection, and a native Gutenberg Block with live previews.
Devinlabs Unit Conventer Developer Profile
2 plugins · 20 total installs
How We Detect Devinlabs Unit Conventer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_rbrotherid="quantityconverter"id="fromconverter"id="resultconverter"id="toconverter"