EH Mortgage Calculator – Loan & Amortization Calculator Security & Risk Analysis

wordpress.org/plugins/eh-mortgage-calculator

A modern mortgage and loan calculator with a clean amortization schedule, monthly payment breakdown, shortcode, and Gutenberg block.

10 active installs v3.1.1 PHP + WP 5.0+ Updated Jan 18, 2026
amortizationfinanceloan-calculatormortgage-calculatorreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EH Mortgage Calculator – Loan & Amortization Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

EH Mortgage Calculator – Loan & Amortization Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The eh-mortgage-calculator plugin version 3.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed solely via prepared statements, and a high percentage of properly escaped output are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs), suggesting a history of secure development or diligent patching by users. The limited attack surface, consisting of a single shortcode with no explicitly identified unprotected entry points, is also a positive sign.

However, the analysis does highlight a potential area for improvement. The complete lack of nonce checks across all identified entry points is a concern. While the current attack surface is small, the absence of nonces means that if any of these entry points were to become exposed or if future functionality were added without proper checks, they could be susceptible to Cross-Site Request Forgery (CSRF) attacks. The capability check is present, which is good, but it doesn't entirely mitigate the risk of CSRF without nonces.

In conclusion, eh-mortgage-calculator v3.1.1 appears to be a relatively secure plugin with a clean history and good coding practices in many areas. The primary weakness lies in the absence of nonce checks. If the plugin's functionality remains limited and no new entry points are introduced, the risk may be contained. However, for long-term security and adherence to WordPress best practices, implementing nonce checks on the shortcode is highly recommended.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

EH Mortgage Calculator – Loan & Amortization Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EH Mortgage Calculator – Loan & Amortization Calculator Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

EH Mortgage Calculator – Loan & Amortization Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
229 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped239 total outputs
Attack Surface

EH Mortgage Calculator – Loan & Amortization Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[eh_mortgage_calculator] includes\class-ehmc-loader.php:37
WordPress Hooks 8
actionadmin_menuincludes\class-ehmc-admin.php:5
filterscript_module_data_ehmc-frontendincludes\class-ehmc-assets.php:34
actionenqueue_block_editor_assetsincludes\class-ehmc-blocks.php:8
actionplugins_loadedincludes\class-ehmc-loader.php:27
actionwp_enqueue_scriptsincludes\class-ehmc-loader.php:32
actioninitincludes\class-ehmc-loader.php:42
actionadmin_initincludes\class-ehmc-loader.php:47
actionadmin_enqueue_scriptsincludes\class-ehmc-loader.php:52
Maintenance & Trust

EH Mortgage Calculator – Loan & Amortization Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

EH Mortgage Calculator – Loan & Amortization Calculator Developer Profile

edgarr41

2 plugins · 40 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EH Mortgage Calculator – Loan & Amortization Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eh-mortgage-calculator/admin/admin-scripts.js/wp-content/plugins/eh-mortgage-calculator/admin/admin-styles.css/wp-content/plugins/eh-mortgage-calculator/assets/css/bootstrap-custom.css/wp-content/plugins/eh-mortgage-calculator/assets/js/chart.umd.min.js/wp-content/plugins/eh-mortgage-calculator/assets/js/frontend.js/wp-content/plugins/eh-mortgage-calculator/blocks/ehmc-calculator/editor.css/wp-content/plugins/eh-mortgage-calculator/blocks/ehmc-calculator/editor.js
Script Paths
/wp-content/plugins/eh-mortgage-calculator/assets/js/chart.umd.min.js/wp-content/plugins/eh-mortgage-calculator/assets/js/frontend.js/wp-content/plugins/eh-mortgage-calculator/blocks/ehmc-calculator/editor.js/wp-content/plugins/eh-mortgage-calculator/admin/admin-scripts.js
Version Parameters
eh-mortgage-calculator/assets/css/bootstrap-custom.css?ver=eh-mortgage-calculator/assets/js/frontend.js?ver=eh-mortgage-calculator/blocks/ehmc-calculator/editor.css?ver=eh-mortgage-calculator/blocks/ehmc-calculator/editor.js?ver=eh-mortgage-calculator/admin/admin-scripts.js?ver=eh-mortgage-calculator/admin/admin-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
ehmc-calculator-containerehmc-calculator-wrapperehmc-calculator-inputsehmc-calculator-outputehmc-calculator-chart
Data Attributes
data-instance-id
JS Globals
EHMC_Elements
Shortcode Output
<!-- EH Mortgage Calculator Block Start --><!-- EH Mortgage Calculator Block End -->
FAQ

Frequently Asked Questions about EH Mortgage Calculator – Loan & Amortization Calculator