
AC's Retirement Savings Calculator Security & Risk Analysis
wordpress.org/plugins/fc-retirement-savings-calculatorA retirement calculator to create date-based schedules. Learn how much to save. Rebrandable. Supports 90 currencies, 6 date formats, and 15 languages.
Is AC's Retirement Savings Calculator Safe to Use in 2026?
Generally Safe
Score 100/100AC's Retirement Savings Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fc-retirement-savings-calculator" plugin version 2.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong positive indicators. Furthermore, the presence of nonce and capability checks, along with a single entry point (a shortcode) that appears to be protected by these checks, suggests a deliberate effort towards secure coding practices. The vulnerability history is also completely clean, with no known CVEs, which is highly encouraging.
However, a significant area of concern lies in the output escaping. With 139 total outputs and only 71% properly escaped, there's a substantial portion (29%) of outputs that are not adequately sanitized. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in these unescaped outputs. While the taint analysis shows no flows, this is likely due to the limited scope of the analysis or the absence of specific taint sources being tested. The lack of any recorded vulnerabilities in the past is a positive trend but does not guarantee future security, especially given the identified output escaping issue.
In conclusion, the plugin has a solid foundation with several secure coding practices implemented. The primary weakness identified is the insufficient output escaping, which requires immediate attention to mitigate potential XSS risks. The absence of past vulnerabilities is a good sign, but the current analysis highlights a specific area for improvement.
Key Concerns
- Insufficient output escaping detected
AC's Retirement Savings Calculator Security Vulnerabilities
AC's Retirement Savings Calculator Code Analysis
Output Escaping
AC's Retirement Savings Calculator Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
AC's Retirement Savings Calculator Maintenance & Trust
Maintenance Signals
Community Trust
AC's Retirement Savings Calculator Alternatives
AC's Retirement Age Calculator
fc-retirement-age-calculator
A retirement calculator to calculate retirement age and create date-based plans. Rebrandable. Supports 90 currencies, 6 date formats, 15 languages.
AC's Retirement Nest Egg Calculator
fc-retirement-nest-egg-calculator
A retirement future value calculator to create date based schedules and charts. Rebrandable. Supports 90 currencies, 6 date formats, and 15 languages.
AC's Retirement Savings Calculator Developer Profile
7 plugins · 2K total installs
How We Detect AC's Retirement Savings Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fc-retirement-savings-calculator/dist/css/bootstrap-reboot-scoped.css/wp-content/plugins/fc-retirement-savings-calculator/dist/css/accurate-calculators.css/wp-content/plugins/fc-retirement-savings-calculator/dist/css/accurate-calculators-custom.css/wp-content/plugins/fc-retirement-savings-calculator/dist/js/interface.RETIRE-SAVINGS.gpl.js/wp-content/plugins/fc-retirement-savings-calculator/dist/js/interface.RETIRE-SAVINGS.gpl.jsfc-retirement-savings-calculator/dist/css/bootstrap-reboot-scoped.css?ver=fc-retirement-savings-calculator/dist/css/accurate-calculators.css?ver=fc-retirement-savings-calculator/dist/css/accurate-calculators-custom.css?ver=fc-retirement-savings-calculator/dist/js/interface.RETIRE-SAVINGS.gpl.js?ver=HTML / DOM Fingerprints
ac-retirement-savings-calculator-containerac-retirement-calculator-input-groupac-retirement-calculator-labelac-retirement-calculator-valueThe following consts must be kept in sync with the CSS variablesdata-op_currencydata-op_date_maskdata-op_theme_base_font_sizedata-op_theme_primary_colordata-op_theme_primary_color_hoverdata-op_theme_primary_color_light+31 moreshow_fcretiresavings_plugin[fcretiresavingsplugin]