
Formulas Security & Risk Analysis
wordpress.org/plugins/formulasAutomotive formulas for car enthusiast web sites
Is Formulas Safe to Use in 2026?
Generally Safe
Score 85/100Formulas has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "formulas" plugin v0.1 exhibits a strong initial security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and any recorded vulnerabilities are all positive indicators. The fact that 100% of SQL queries use prepared statements and outputs are properly escaped suggests good development practices in these critical areas. Furthermore, the plugin has no known CVEs, and its vulnerability history is clean, which is reassuring.
However, the analysis does highlight potential areas of concern, primarily stemming from the limited scope of the analysis itself and the plugin's early version. The plugin has a single entry point via a shortcode, and importantly, no capability checks or nonce checks are documented. While there are no direct vulnerabilities detected in the code signals or taint analysis, the lack of authentication and authorization checks on its entry points, even with a seemingly small attack surface, presents a risk. Future versions or more complex functionality could easily introduce vulnerabilities if these checks are not implemented. The absence of taint analysis flows might indicate simple code or a lack of data handling that could be exploited if the plugin evolves.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
Formulas Security Vulnerabilities
Formulas Code Analysis
Formulas Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Formulas Maintenance & Trust
Maintenance Signals
Community Trust
Formulas Alternatives
CarDealerPress
cardealerpress
In order to use CarDealerPress a subscription is required with DealerTrend. The plugin utilizes their API to pull automotive data.
Vehizo
vehizo-vehicle-management
Professional vehicle management for WordPress. Perfect for car dealerships with advanced filtering and contact forms.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
TinyPNG – JPEG, PNG & WebP image compression
tiny-compress-images
Speed up your website. Optimize your JPEG, PNG, and WebP images automatically with TinyPNG.
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
Formulas Developer Profile
7 plugins · 10K total installs
How We Detect Formulas
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formulas/formulas.css/wp-content/plugins/formulas/formulas.jsformulas/formulas.css?ver=formulas/formulas.js?ver=HTML / DOM Fingerprints
formulasformulas-edformulas-ed-rowformulas-ed-labelformulas-inputformulas-ed-boreformulas-ed-strokeformulas-ed-cylinders+13 moreid="formulas_ed_name="formulas_ed_id="formulas_ed_class="formulas-input formulas-ed-placeholder="id="formulas_cr_+5 more<div class="formulas formulas-ed"<form action="" name="formulas_ed_<label for="formulas_ed_<input type="text" name="formulas_ed_