AC's Mortgage Calculator Security & Risk Analysis

wordpress.org/plugins/fc-mortgage-calculator

A mortgage calculator supporting down payments, points & more. Create date-based schedules. Supports 90 currencies, 6 date formats, 15 languages.

300 active installs v2.1 PHP + WP 5.8+ Updated Aug 17, 2025
amortization-schedulecalculatormortgage-calculatorpayment-calculatorpayment-schedule
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AC's Mortgage Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

AC's Mortgage Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The fc-mortgage-calculator plugin version 2.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The presence of nonce and capability checks on its single entry point (a shortcode) suggests basic security awareness. However, a significant concern arises from the output escaping, with only 61% of outputs properly escaped. This leaves a substantial portion of user-facing output potentially vulnerable to cross-site scripting (XSS) attacks if the plugin handles user-supplied data in these unescaped outputs. The lack of any reported CVEs or taint analysis findings is encouraging and suggests a history of relative security, but it's crucial not to let the good history lull developers into complacency, especially given the identified output escaping weakness.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

AC's Mortgage Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AC's Mortgage Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
61
94 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped155 total outputs
Attack Surface

AC's Mortgage Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fcmortgageplugin] fc-mortgage-calculator.php:1896
WordPress Hooks 5
actionwp_enqueue_scriptsfc-mortgage-calculator.php:998
actioninitfc-mortgage-calculator.php:1011
actionwidgets_initfc-mortgage-calculator.php:1892
filterscript_loader_tagfc-mortgage-calculator.php:1911
actionadmin_enqueue_scriptsfc-mortgage-calculator.php:1927
Maintenance & Trust

AC's Mortgage Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 17, 2025
PHP min version
Downloads14K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

AC's Mortgage Calculator Developer Profile

karl53

7 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AC's Mortgage Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fc-mortgage-calculator/dist/css/bootstrap-reboot-scoped.css/wp-content/plugins/fc-mortgage-calculator/dist/css/accurate-calculators.css/wp-content/plugins/fc-mortgage-calculator/dist/css/accurate-calculators-custom.css/wp-content/plugins/fc-mortgage-calculator/dist/js/interface.MORTGAGE.gpl.js
Script Paths
/wp-content/plugins/fc-mortgage-calculator/dist/js/interface.MORTGAGE.gpl.js
Version Parameters
fc-mortgage-calculator/dist/css/bootstrap-reboot-scoped.css?ver=fc-mortgage-calculator/dist/css/accurate-calculators.css?ver=fc-mortgage-calculator/dist/css/accurate-calculators-custom.css?ver=fc-mortgage-calculator/dist/js/interface.MORTGAGE.gpl.js?ver=

HTML / DOM Fingerprints

CSS Classes
fcmortgageplugin-container
HTML Comments
AccurateCalculators.com mortgage calculator plugin Copyright (c) 2025 AccurateCalculators.com https://AccurateCalculators.com This is an add-on for WordPress+64 more
Data Attributes
data-fcmortgage-plugin-settings
JS Globals
fcmortgagepluginmortgagepluginfc_mortloan_verFC_MORTLOAN_VERFC_MORTLOAN_PLUGIN_NAMEFC_MORTLOAN_CSS_SCOPED_RESET+9 more
Shortcode Output
[fcmortgageplugin[fcmortgageplugin
FAQ

Frequently Asked Questions about AC's Mortgage Calculator