Ecu Remapping Performance Calculator Security & Risk Analysis

wordpress.org/plugins/ecu-remapping-performance-calculator

This plugin allows you to calculate the performance gains of remapping an ECU. Allow website users to choose their vehicle type, engine type, make/mod …

40 active installs v3.2 PHP 5.2.4+ WP 3.8+ Updated Nov 18, 2025
ecuperformance-calculatorremapping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ecu Remapping Performance Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

Ecu Remapping Performance Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'ecu-remapping-performance-calculator' plugin v3.2 exhibits a generally good security posture, with several key security measures in place. The absence of known CVEs and a clean vulnerability history is a significant strength. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks for a majority of its entry points. Furthermore, the plugin does not bundle any libraries, which avoids potential vulnerabilities associated with outdated bundled components.

However, there are areas that warrant attention. The static analysis revealed two flows with unsanitized paths, which, although not flagged as critical or high severity in the taint analysis, represent potential vectors for exploitation if not handled carefully. While the majority of output is properly escaped (89%), the remaining 11% could still lead to cross-site scripting (XSS) vulnerabilities in specific scenarios. The presence of external HTTP requests, while not inherently a vulnerability, increases the attack surface and requires careful monitoring for any potential vulnerabilities in the external services it communicates with.

In conclusion, the plugin is relatively secure, particularly given its lack of historical vulnerabilities. The primary concerns stem from the two unsanitized path flows and the percentage of unescaped output. Addressing these specific code signals, along with robust monitoring of external dependencies, would further solidify its security.

Key Concerns

  • Flows with unsanitized paths detected
  • 11% of output not properly escaped
Vulnerabilities
None known

Ecu Remapping Performance Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ecu Remapping Performance Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
19
151 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

89% escaped170 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
arrowD182378_updateErpcSettingsObjects (admin\main_handlers.php:386)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ecu Remapping Performance Calculator Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 7

authwp_ajax_arrowD182378_ecuRemapCalcValidator_returnDataToJsadmin\erpc_core.php:564
noprivwp_ajax_arrowD182378_ecuRemapCalcValidator_returnDataToJsadmin\erpc_core.php:565
authwp_ajax_arrowD182378_ecuRemapCalcValidator_returnFinalResultsadmin\erpc_core.php:588
noprivwp_ajax_arrowD182378_ecuRemapCalcValidator_returnFinalResultsadmin\erpc_core.php:589
authwp_ajax_arrowd182378_remove_plugin_optionsadmin\erpc_wp_options.php:264
authwp_ajax_arrowD182378_updateErpcSettingsObjectsadmin\main_handlers.php:440
authwp_ajax_arrowd182378_saveApiSettingsadmin\main_handlers.php:508

Shortcodes 1

[ECU_Tuning_Performance_Calculator] admin\erpc_formRender.php:50
WordPress Hooks 11
actionadmin_menuadmin\admin.php:10
actionadmin_menuadmin\erpc_core.php:17
actionadmin_enqueue_scriptsadmin\erpc_core.php:34
actionwp_enqueue_scriptsadmin\erpc_core.php:35
actionwp_enqueue_scriptsadmin\erpc_formRender.php:48
filterplugin_row_metaecu-remapping-performance-calculator.php:81
actionadmin_enqueue_scriptsecu-remapping-performance-calculator.php:84
actionwp_enqueue_scriptsecu-remapping-performance-calculator.php:108
actionadmin_enqueue_scriptsecu-remapping-performance-calculator.php:109
actionwp_enqueue_scriptsecu-remapping-performance-calculator.php:120
actionadmin_enqueue_scriptsecu-remapping-performance-calculator.php:121
Maintenance & Trust

Ecu Remapping Performance Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 18, 2025
PHP min version5.2.4
Downloads974

Community Trust

Rating100/100
Number of ratings5
Active installs40
Developer Profile

Ecu Remapping Performance Calculator Developer Profile

Irish_Cathal

8 plugins · 640 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ecu Remapping Performance Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecu-remapping-performance-calculator/admin/styles/style.css/wp-content/plugins/ecu-remapping-performance-calculator/admin/js/admin_logic.js/wp-content/plugins/ecu-remapping-performance-calculator/admin/js/admin-deactivate-confirm.js
Script Paths
/wp-content/plugins/ecu-remapping-performance-calculator/admin/js/admin-deactivate-confirm.js/wp-content/plugins/ecu-remapping-performance-calculator/admin/js/admin_logic.js
Version Parameters
ecu-remapping-performance-calculator/admin/styles/style.css?ver=ecu-remapping-performance-calculator/admin/js/admin_logic.js?ver=ecu-remapping-performance-calculator/admin/js/admin-deactivate-confirm.js?ver=

HTML / DOM Fingerprints

CSS Classes
intro_text_classtst
Data Attributes
arrowd182378_ajax_object
JS Globals
arrowd182378_ajax_objarrowd182378_ajax_object
REST Endpoints
/wp-json/ecu-remap/v1
FAQ

Frequently Asked Questions about Ecu Remapping Performance Calculator