
JKL Unit Converter Security & Risk Analysis
wordpress.org/plugins/jkl-unit-converterA simple Unit Converter widget that allows you to between various units. (Inspired by Google's Unit Converter.)
Is JKL Unit Converter Safe to Use in 2026?
Generally Safe
Score 85/100JKL Unit Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jkl-unit-converter" plugin v1.0.0 exhibits a generally good security posture based on the static analysis provided. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are significant strengths. The presence of a nonce check and a high percentage of properly escaped output further bolster its security. The zero recorded CVEs also suggest a history of responsible development or a lack of past exploitation, which is positive.
However, a notable concern is the lack of capability checks on the single identified shortcode. While the total attack surface is small and there are no unprotected entry points detected at the AJAX or REST API level, the shortcode represents a potential vector for unauthorized actions if it performs sensitive operations. The taint analysis showing zero flows is reassuring, but this could be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin. Overall, the plugin is well-developed from a security perspective, but the missing capability check on the shortcode warrants attention to ensure all potential entry points are adequately secured.
Key Concerns
- Shortcode without capability check
JKL Unit Converter Security Vulnerabilities
JKL Unit Converter Code Analysis
Output Escaping
JKL Unit Converter Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
JKL Unit Converter Maintenance & Trust
Maintenance Signals
Community Trust
JKL Unit Converter Alternatives
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
JKL Timezone Converter
jkl-timezone-converter
A simple Timezone widget and shortcode that allows you to convert time differences and easily plan events or meetings based in other timezones.
Content Holder
content-holder
Separate your content into reusable parts to use anywhere in your site through a function, shortcode or widget
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Get Custom Field Values
get-custom-field-values
Use widgets, shortcodes, and/or template tags to easily retrieve and display custom field values for posts or pages.
JKL Unit Converter Developer Profile
4 plugins · 130 total installs
How We Detect JKL Unit Converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jkl-unit-converter/style.css/wp-content/plugins/jkl-unit-converter/js/functions.js/wp-content/plugins/jkl-unit-converter/js/list-choice.js/wp-content/plugins/jkl-unit-converter/js/list-units.js/wp-content/plugins/jkl-unit-converter/js/functions.js/wp-content/plugins/jkl-unit-converter/js/list-choice.js/wp-content/plugins/jkl-unit-converter/js/list-units.jsjkl-unit-converter/style.css?ver=jkl-unit-converter/js/functions.js?ver=jkl-unit-converter/js/list-choice.js?ver=jkl-unit-converter/js/list-units.js?ver=HTML / DOM Fingerprints
<!-- JKL Unit Converter Widget -->[jkluc]