Diet Calorie Calculator Security & Risk Analysis

wordpress.org/plugins/diet-calorie-calculator

Diet Calorie Calculator - elegant and effective calorie calculator solution for health experts, fitness trainers and nutrition coaches.

100 active installs v1.1.1 PHP 7.3+ WP 5.0+ Updated Mar 6, 2025
bmr-calculatorcalorie-calculatormacrosnutritionweight-loss
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 21, 2026
Safety Verdict

Is Diet Calorie Calculator Safe to Use in 2026?

Mostly Safe

Score 70/100

Diet Calorie Calculator is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Feb 21, 2026Updated 1yr ago
Risk Assessment

The "diet-calorie-calculator" v1.1.1 plugin presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a very high percentage of properly escaped output, which mitigates common injection and XSS vulnerabilities. The absence of known CVEs and any recorded past vulnerabilities is also a strong indicator of a generally well-maintained and secure codebase. However, a significant concern arises from the large attack surface exposed through AJAX handlers. With 8 AJAX handlers, all of which lack authentication checks, this presents a substantial risk for unauthorized actions or information disclosure. While taint analysis shows no critical or high severity flows and no dangerous functions are used, the presence of two flows with unsanitized paths, although not deemed critical, warrants further investigation. The plugin also has external HTTP requests, which could be a vector if not handled securely. Overall, while the plugin excels in data handling and output sanitization, the lack of authentication on a majority of its entry points, particularly AJAX handlers, is a critical weakness that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
1 published

Diet Calorie Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-39680medium · 5.3Missing Authorization

Diet Calorie Calculator <= 1.1.1 - Missing Authorization

Feb 21, 2026Unpatched
Version History

Diet Calorie Calculator Release Timeline

v1.1.1Current1 CVE
v1.1.01 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Diet Calorie Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
121 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped123 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_ajax_request (admin\class-mwp-dcc-admin.php:292)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Diet Calorie Calculator Attack Surface

Entry Points9
Unprotected8

AJAX Handlers 8

authwp_ajax_dcc_connect_klaviyoincludes\class-mwp-dcc.php:165
noprivwp_ajax_dcc_connect_klaviyoincludes\class-mwp-dcc.php:166
authwp_ajax_dcc_connect_zapierincludes\class-mwp-dcc.php:167
noprivwp_ajax_dcc_connect_zapierincludes\class-mwp-dcc.php:168
authwp_ajax_dcc_test_emailincludes\class-mwp-dcc.php:169
noprivwp_ajax_dcc_test_emailincludes\class-mwp-dcc.php:170
noprivwp_ajax_dcc_form_processingincludes\class-mwp-dcc.php:188
authwp_ajax_dcc_form_processingincludes\class-mwp-dcc.php:189

Shortcodes 1

[dcc_calc] includes\class-mwp-dcc.php:187
WordPress Hooks 8
actionplugins_loadedincludes\class-mwp-dcc.php:146
actionadmin_enqueue_scriptsincludes\class-mwp-dcc.php:160
actionadmin_enqueue_scriptsincludes\class-mwp-dcc.php:161
actionadmin_menuincludes\class-mwp-dcc.php:162
actionadmin_initincludes\class-mwp-dcc.php:163
actioninitincludes\class-mwp-dcc.php:164
actionwp_enqueue_scriptsincludes\class-mwp-dcc.php:185
actionwp_enqueue_scriptsincludes\class-mwp-dcc.php:186
Maintenance & Trust

Diet Calorie Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 6, 2025
PHP min version7.3
Downloads3K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Diet Calorie Calculator Developer Profile

MWP Development

1 plugin · 100 total installs

73
trust score
Avg Security Score
70/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Diet Calorie Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/diet-calorie-calculator/admin/css/mwp-dcc-admin.min.css
Script Paths
/wp-content/plugins/diet-calorie-calculator/admin/js/mwp-dcc-admin.min.js
Version Parameters
mwp-dcc-gfont-robotomwp-dcc-admindiet-calorie-calculator/admin/css/mwp-dcc-admin.min.css?ver=diet-calorie-calculator/admin/js/mwp-dcc-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
mwp-dcc-wrap
JS Globals
dccAdminVars
FAQ

Frequently Asked Questions about Diet Calorie Calculator