JIMMO WP Property Finance Budget Calculator Security & Risk Analysis

wordpress.org/plugins/jimmo-wp-property-finance-budget-calculator

Display a loan budget calculator on your website, where visitors can check how much loan or mortgage they can afford, and show an amortization plan.

20 active installs v1.1.0 PHP + WP 3.6.0+ Updated Unknown
equityloanloan-budgetloan-budget-calculatormortgage
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JIMMO WP Property Finance Budget Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

JIMMO WP Property Finance Budget Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "jimmo-wp-property-finance-budget-calculator" plugin version 1.1.0 demonstrates a mixed security posture. On the positive side, it shows strong adherence to secure coding practices with no detected dangerous functions, SQL injection vulnerabilities through the exclusive use of prepared statements, and no file operations or external HTTP requests. The complete absence of recorded vulnerabilities in its history also suggests a relatively mature and secure development lifecycle.

However, significant concerns arise from the plugin's attack surface. The presence of two AJAX handlers that lack authentication checks presents a clear risk. These unprotected entry points could potentially be exploited by unauthenticated users to trigger unintended actions or expose sensitive information, depending on the functionality they handle. While taint analysis did not reveal any specific issues, the lack of proper capability checks on these AJAX handlers is a critical oversight that amplifies their risk. The proper escaping of output is also not perfect, with 23% of outputs potentially unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in areas like SQL handling, the unprotected AJAX endpoints represent a substantial weakness. These entry points, coupled with the lack of capability checks and imperfect output escaping, warrant immediate attention to mitigate potential security risks.

Key Concerns

  • AJAX handlers without authentication
  • Lack of capability checks
  • Unescaped output
Vulnerabilities
None known

JIMMO WP Property Finance Budget Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JIMMO WP Property Finance Budget Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped13 total outputs
Attack Surface
2 unprotected

JIMMO WP Property Finance Budget Calculator Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_calculate_ammortization_scheduleincludes\class-jimmo-wp-property-finance-budget-calculator.php:187
noprivwp_ajax_calculate_ammortization_scheduleincludes\class-jimmo-wp-property-finance-budget-calculator.php:188

Shortcodes 1

[jw-budget-calculator] public\class-jimmo-wp-property-finance-budget-calculator-public.php:114
WordPress Hooks 9
filterlocaleincludes\class-jimmo-wp-property-finance-budget-calculator-i18n.php:61
actioninitincludes\class-jimmo-wp-property-finance-budget-calculator.php:149
actionadmin_enqueue_scriptsincludes\class-jimmo-wp-property-finance-budget-calculator.php:164
actionadmin_menuincludes\class-jimmo-wp-property-finance-budget-calculator.php:166
actionadmin_initincludes\class-jimmo-wp-property-finance-budget-calculator.php:167
actionadmin_noticesincludes\class-jimmo-wp-property-finance-budget-calculator.php:168
actionwp_enqueue_scriptsincludes\class-jimmo-wp-property-finance-budget-calculator.php:184
actionwp_enqueue_scriptsincludes\class-jimmo-wp-property-finance-budget-calculator.php:185
actioninitincludes\class-jimmo-wp-property-finance-budget-calculator.php:186
Maintenance & Trust

JIMMO WP Property Finance Budget Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

JIMMO WP Property Finance Budget Calculator Developer Profile

netjet

2 plugins · 30 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JIMMO WP Property Finance Budget Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jimmo-wp-property-finance-budget-calculator/admin/css/jimmo-wp-property-finance-budget-calculator-admin.css/wp-content/plugins/jimmo-wp-property-finance-budget-calculator/admin/js/jimmo-wp-property-finance-budget-calculator-admin.js/wp-content/plugins/jimmo-wp-property-finance-budget-calculator/includes/js/jimmo-wp-property-finance-budget-calculator.js
Script Paths
admin/js/jimmo-wp-property-finance-budget-calculator-admin.jsincludes/js/jimmo-wp-property-finance-budget-calculator.js
Version Parameters
jimmo-wp-property-finance-budget-calculator/admin/css/jimmo-wp-property-finance-budget-calculator-admin.css?ver=jimmo-wp-property-finance-budget-calculator/admin/js/jimmo-wp-property-finance-budget-calculator-admin.js?ver=jimmo-wp-property-finance-budget-calculator/includes/js/jimmo-wp-property-finance-budget-calculator.js?ver=

HTML / DOM Fingerprints

CSS Classes
jimmo-wp-property-finance-budget-calculator-options-pagejimmo-wp-property-finance-budget-calculator-credits
HTML Comments
<!-- JIMMO WP Property Finance Budget Calculator Options Page -->
Data Attributes
data-plugin-name="jimmo-wp-property-finance-budget-calculator"data-plugin-version="1.1.0"
JS Globals
jimmo_wp_property_finance_budget_calculator_admin_params
FAQ

Frequently Asked Questions about JIMMO WP Property Finance Budget Calculator