AC's Loan Calculator Security & Risk Analysis

wordpress.org/plugins/fc-loan-calculator

A versatile loan calculator with a date-based amortization schedule and charts. Rebrandable. Supports 90 currencies, 6 date formats, and 15 languages.

500 active installs v2.1 PHP + WP 5.8+ Updated Aug 17, 2025
amortizationfinanceloan-calculatormortgagepayment-calculator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AC's Loan Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

AC's Loan Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The fc-loan-calculator plugin version 2.1 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and file operations significantly limits the potential attack surface. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries and implements nonce and capability checks, indicating good development practices for handling sensitive operations. The lack of any recorded vulnerabilities, including critical or high-severity ones, in its history further reinforces this positive assessment. However, a notable area for improvement lies in output escaping, where a substantial portion (26%) of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly included in these outputs without sanitization. The absence of taint analysis results is also a minor concern, as it limits the ability to detect potential data flow vulnerabilities.

Despite the promising aspects, the unescaped output presents a tangible risk that needs to be addressed. While the plugin has a clean vulnerability history, this should not lead to complacency. Future development should focus on ensuring all output is correctly escaped to prevent potential XSS attacks. The plugin's strengths lie in its minimal attack surface and adherence to core security practices like prepared statements and authentication checks. The main weakness, however, is the potential for XSS due to incomplete output escaping.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

AC's Loan Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AC's Loan Calculator Release Timeline

v2.1Current
v2.0
v1.5.4.1
v1.5.4
v1.5.2
v1.5
v1.4.4
v1.4.3
v1.4.2
v1.4.0
v1.3
v1.2.1
v1.2.0
v1.1.2
v1.1.2.b
v1.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

AC's Loan Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
88 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped119 total outputs
Attack Surface

AC's Loan Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fcloanplugin] fc-loan-calculator.php:1679
WordPress Hooks 5
actionwp_enqueue_scriptsfc-loan-calculator.php:912
actioninitfc-loan-calculator.php:925
actionwidgets_initfc-loan-calculator.php:1675
filterscript_loader_tagfc-loan-calculator.php:1694
actionadmin_enqueue_scriptsfc-loan-calculator.php:1710
Maintenance & Trust

AC's Loan Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 17, 2025
PHP min version
Downloads0

Community Trust

Rating74/100
Number of ratings3
Active installs500
Developer Profile

AC's Loan Calculator Developer Profile

karl53

7 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AC's Loan Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fc-loan-calculator/dist/css/bootstrap-reboot-scoped.css/wp-content/plugins/fc-loan-calculator/dist/css/accurate-calculators.css/wp-content/plugins/fc-loan-calculator/dist/css/accurate-calculators-custom.css/wp-content/plugins/fc-loan-calculator/dist/js/interface.LOAN.gpl.js
Script Paths
dist/js/interface.LOAN.gpl.js
Version Parameters
fc-loan-calculator/dist/css/bootstrap-reboot-scoped.css?ver=fc-loan-calculator/dist/css/accurate-calculators.css?ver=fc-loan-calculator/dist/css/accurate-calculators-custom.css?ver=fc-loan-calculator/dist/js/interface.LOAN.gpl.js?ver=

HTML / DOM Fingerprints

CSS Classes
ac-loan-calculator
HTML Comments
example error logging.Prefixes:Option array:[KT] 08/21/2024 - new options+6 more
Data Attributes
sc_sizesc_custom_stylesc_add_linksc_brand_namesc_hide_resizesc_loan_amt+78 more
JS Globals
ac_rendered_modalsac_rendered_conventions
Shortcode Output
[fcloanplugin
FAQ

Frequently Asked Questions about AC's Loan Calculator