Forex Calculators Security & Risk Analysis

wordpress.org/plugins/fx-calculators

Integrate five essential forex calculators into your site, providing accurate financial analysis for both experienced traders and beginners.

200 active installs v1.3.11 PHP 5.6+ WP 3.0.0+ Updated Feb 21, 2026
forex-tradinglot-sizemarginpip-valueposition-size
99
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 27, 2025
Download
Safety Verdict

Is Forex Calculators Safe to Use in 2026?

Generally Safe

Score 99/100

Forex Calculators has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 27, 2025Updated 1mo ago
Risk Assessment

The fx-calculators plugin, in version 1.3.11, exhibits a generally good security posture, particularly in its handling of output escaping and lack of file operations or external HTTP requests. The static analysis reveals a robust implementation with a high percentage of SQL queries using prepared statements and a near-perfect rate of output escaping. The presence of nonce and capability checks on entry points, while minimal, is a positive indicator. However, the plugin's vulnerability history is a significant concern. Two medium-severity vulnerabilities have been recorded, with common types including Missing Authorization and Cross-site Scripting. The fact that these vulnerabilities have occurred, even if currently patched, suggests a recurring pattern of potential oversight in secure coding practices. While the current static analysis does not reveal any immediate critical or high-severity flaws, the historical context warrants caution.

Key Concerns

  • Two medium severity CVEs in history
  • Vulnerabilities indicate potential authorization/XSS flaws
Vulnerabilities
2

Forex Calculators Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-13716medium · 4.3Missing Authorization

Forex Calculators <= 1.3.7 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Feb 27, 2025 Patched in 1.3.8 (4d)
CVE-2025-22689medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Forex Calculators <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Jan 31, 2025 Patched in 1.3.7 (25d)
Code Analysis
Analyzed Mar 16, 2026

Forex Calculators Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
2
169 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

99% escaped171 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_settings_callback (forex-calculators.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Forex Calculators Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 1

authwp_ajax_fxcalc_settingsforex-calculators.php:93

Shortcodes 10

[fxcalc_margin] forex-calculators.php:44
[fxcalc_pipvalue] forex-calculators.php:45
[fxcalc_profit] forex-calculators.php:46
[fxcalc_lotsize] forex-calculators.php:47
[fxcalc_rrwinrate] forex-calculators.php:48
[margin] forex-calculators.php:53
[pipvalue] forex-calculators.php:58
[profit] forex-calculators.php:63
[lotsize] forex-calculators.php:68
[rrwinrate] forex-calculators.php:73
WordPress Hooks 9
actionadmin_menuforex-calculators.php:38
actioninitforex-calculators.php:39
actionadmin_initforex-calculators.php:90
actionadmin_initforex-calculators.php:91
actionadmin_initforex-calculators.php:92
actionadmin_noticesforex-calculators.php:94
actionadmin_noticesforex-calculators.php:152
actionadmin_enqueue_scriptsforex-calculators.php:210
actionwp_enqueue_scriptsforex-calculators.php:211
Maintenance & Trust

Forex Calculators Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 21, 2026
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Forex Calculators Developer Profile

Levan Tarbor

1 plugin · 200 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Forex Calculators

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fx-calculators/styles.min.css/wp-content/plugins/fx-calculators/loader.min.js
Script Paths
/wp-content/plugins/fx-calculators/loader.min.js
Version Parameters
fx-calculators/styles.min.css?ver=1.3.11fx-calculators/loader.min.js?ver=1.3.11

HTML / DOM Fingerprints

CSS Classes
fxcalc-reviewfxcalc-review-btnfxcalc-ms
REST Endpoints
/wp-json/fxcalc/settings
Shortcode Output
[fxcalc_margin][fxcalc_pipvalue][fxcalc_profit][fxcalc_lotsize]
FAQ

Frequently Asked Questions about Forex Calculators