
Easy Mortgage Rates Security & Risk Analysis
wordpress.org/plugins/easy-mortgage-ratesThis plugin will allow you to use [easy_mortgage_rates_table] as a template tag to insert a table of common real estate loan program interest rates in …
Is Easy Mortgage Rates Safe to Use in 2026?
Generally Safe
Score 85/100Easy Mortgage Rates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-mortgage-rates" v.2 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs in its history and the use of prepared statements for all SQL queries are strong indicators of good development practices. The plugin also correctly identifies and implements a capability check for its single entry point.
However, there are several concerning areas. The presence of unsanitized paths in two out of three analyzed taint flows presents a significant risk, potentially allowing for directory traversal or other path manipulation vulnerabilities. Furthermore, only 20% of output is properly escaped, leaving the plugin susceptible to cross-site scripting (XSS) attacks. The lack of nonce checks on its sole entry point, despite the presence of a capability check, is a missed opportunity to further secure the functionality from CSRF attacks.
In conclusion, while the plugin has a clean vulnerability history and good database security, the identified issues with unsanitized paths and insufficient output escaping are critical weaknesses that require immediate attention. The plugin's attack surface is small, but these vulnerabilities, if exploitable, could have severe consequences.
Key Concerns
- Unsanitized paths in taint flows
- Low output escaping percentage
- No nonce check on entry point
Easy Mortgage Rates Security Vulnerabilities
Easy Mortgage Rates Release Timeline
Easy Mortgage Rates Code Analysis
Output Escaping
Data Flow Analysis
Easy Mortgage Rates Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Easy Mortgage Rates Maintenance & Trust
Maintenance Signals
Community Trust
Easy Mortgage Rates Alternatives
Loan Comparison
loan-comparison
A simple way to compare loans from banks and other providers. Uses sliders to set the amount and term and display the number of matching banks.
Mortgage Rates
mortgage-rates
Mortgage rates widget for your blog. Free.
California State Grants
california-state-grants
The California State Grants Plugin is the official WordPress plugin allowing you to manage your grant data within your own site running WordPress.
Skeps Pay-Over-Time
skeps-pay-over-time
Skeps provides Pay-Over-Time options with monthly payment plans including no interest promos.
Easy Mortgage Rates Developer Profile
1 plugin · 10 total installs
How We Detect Easy Mortgage Rates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tabletdcentertickname="30yrfixed[rate]"name="30yrfixed[apr]"name="30yrhigh[rate]"name="30yrhigh[apr]"name="15yrfixed[rate]"name="15yrfixed[apr]"+10 more[easy_mortgage_rates_table]