
Human Bmi Bmr Calculation Security & Risk Analysis
wordpress.org/plugins/human-bmi-bmr-calculationHuman Bmi Bmr Calculation Plugin.
Is Human Bmi Bmr Calculation Safe to Use in 2026?
Generally Safe
Score 100/100Human Bmi Bmr Calculation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "human-bmi-bmr-calculation" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and has no recorded vulnerability history, suggesting a history of stable and secure code. The attack surface is also very small, with only one shortcode and no AJAX handlers or REST API routes detected in the static analysis.
However, there are significant concerns highlighted by the static analysis. The most alarming finding is the complete lack of output escaping, meaning all 12 identified output points are potentially vulnerable to cross-site scripting (XSS) attacks. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if user input is not properly validated before being used in sensitive operations. The absence of nonce checks and capability checks for the single shortcode also presents a risk, as it could be leveraged in cross-site request forgery (CSRF) attacks or unauthorized privilege escalation scenarios.
In conclusion, while the plugin's lack of known vulnerabilities and secure SQL implementation are positive, the critical absence of output escaping and the presence of high-severity taint flows with unsanitized paths are major security weaknesses. The lack of any authorization checks on the shortcode further exacerbates these risks. These issues create a significant potential for XSS and potentially other vulnerabilities, requiring urgent attention.
Key Concerns
- No output escaping detected
- 2 high severity unsanitized taint flows
- No nonce checks on shortcode
- No capability checks on shortcode
Human Bmi Bmr Calculation Security Vulnerabilities
Human Bmi Bmr Calculation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Human Bmi Bmr Calculation Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Human Bmi Bmr Calculation Maintenance & Trust
Maintenance Signals
Community Trust
Human Bmi Bmr Calculation Alternatives
Calculate BMR and BMI
calculate-bmr
Enhance your site with our plugin, easily integrating BMR/BMI calculators into your Pages/Posts
FormsDB – Save Elementor Forms to Google Sheets & Post Type
sb-elementor-contact-form-db
Connect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes
revisionary
Control how published content is updated. Users can duplicate posts and submit changes. Then editors can approve, reject or schedule those changes.
User Submitted Posts – Enable Users to Submit Posts from the Front End
user-submitted-posts
Enable visitors to submit posts and images from the front-end of your site. Many features including anti-spam security, content restriction, and more.
Simple Product Options for WooCommerce
product-options-for-woocommerce
It adds drop-down, radio button and text field options on the product page.
Human Bmi Bmr Calculation Developer Profile
1 plugin · 10 total installs
How We Detect Human Bmi Bmr Calculation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/human-bmi-bmr-calculation/assets/frontEnd/main/main.css/wp-content/plugins/human-bmi-bmr-calculation/assets/frontEnd/main/main.js/wp-content/plugins/human-bmi-bmr-calculation/assets/frontEnd/main/main.jshuman-bmi-bmr-calculation/assets/frontEnd/main/main.css?ver=human-bmi-bmr-calculation/assets/frontEnd/main/main.js?ver=