JIMMO WP Loan Repayment Calculator Security & Risk Analysis

wordpress.org/plugins/jimmo-wp-loan-repayment-calculator

Display a loan repayment calculator, where visitors can calculate a payment plan for their annuity loan, depending on a number of values.

10 active installs v1.1.0 PHP + WP 3.6.0+ Updated May 19, 2017
annuity-loanannuity-loan-repaymentloanloan-repaymentloan-repayment-calculator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JIMMO WP Loan Repayment Calculator Safe to Use in 2026?

Generally Safe

Score 85/100

JIMMO WP Loan Repayment Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "jimmo-wp-loan-repayment-calculator" plugin v1.1.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, all SQL queries are prepared, and there are no recorded vulnerabilities or external HTTP requests. The absence of critical or high-severity taint flows also suggests a generally secure codebase in terms of data handling.

However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers without any authentication or capability checks. This is a critical oversight that could allow unauthenticated users to trigger these handlers, potentially leading to unintended actions or information disclosure depending on the functionality they implement. While there are no recorded CVEs, indicating a lack of publicly known exploits, the presence of unprotected entry points is a serious inherent risk that could be exploited by attackers.

In conclusion, while the plugin avoids common pitfalls like raw SQL or unescaped output in most cases, the unprotected AJAX endpoints are a major weakness. This risk is compounded by the potential for unknown vulnerabilities to exist that could be leveraged through these exposed entry points. A review and hardening of these AJAX handlers are highly recommended.

Key Concerns

  • Unprotected AJAX handlers
  • Low number of capability checks
Vulnerabilities
None known

JIMMO WP Loan Repayment Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

JIMMO WP Loan Repayment Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped11 total outputs
Attack Surface
2 unprotected

JIMMO WP Loan Repayment Calculator Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_repayment_calculate_ammortization_scheduleincludes\class-jimmo-wp-loan-repayment-calculator.php:188
noprivwp_ajax_repayment_calculate_ammortization_scheduleincludes\class-jimmo-wp-loan-repayment-calculator.php:189

Shortcodes 1

[jw-repayment-calculator] public\class-jimmo-wp-loan-repayment-calculator-public.php:105
WordPress Hooks 9
filterlocaleincludes\class-jimmo-wp-loan-repayment-calculator-i18n.php:66
actionplugins_loadedincludes\class-jimmo-wp-loan-repayment-calculator.php:149
actionadmin_enqueue_scriptsincludes\class-jimmo-wp-loan-repayment-calculator.php:164
actionadmin_menuincludes\class-jimmo-wp-loan-repayment-calculator.php:166
actionadmin_initincludes\class-jimmo-wp-loan-repayment-calculator.php:167
actionadmin_noticesincludes\class-jimmo-wp-loan-repayment-calculator.php:168
actionwp_enqueue_scriptsincludes\class-jimmo-wp-loan-repayment-calculator.php:185
actionwp_enqueue_scriptsincludes\class-jimmo-wp-loan-repayment-calculator.php:186
actioninitincludes\class-jimmo-wp-loan-repayment-calculator.php:187
Maintenance & Trust

JIMMO WP Loan Repayment Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedMay 19, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

JIMMO WP Loan Repayment Calculator Developer Profile

netjet

2 plugins · 30 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JIMMO WP Loan Repayment Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jimmo-wp-loan-repayment-calculator/css/jimmo-wp-loan-repayment-calculator-admin.css/wp-content/plugins/jimmo-wp-loan-repayment-calculator/js/jimmo-wp-loan-repayment-calculator-admin.js
Script Paths
/wp-content/plugins/jimmo-wp-loan-repayment-calculator/js/jimmo-wp-loan-repayment-calculator-admin.js
Version Parameters
jimmo-wp-loan-repayment-calculator/css/jimmo-wp-loan-repayment-calculator-admin.css?ver=jimmo-wp-loan-repayment-calculator/js/jimmo-wp-loan-repayment-calculator-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
jlr-credits-nag
FAQ

Frequently Asked Questions about JIMMO WP Loan Repayment Calculator