JKL Unit Converter Security & Risk Analysis

wordpress.org/plugins/jkl-unit-converter

A simple Unit Converter widget that allows you to between various units. (Inspired by Google's Unit Converter.)

90 active installs v1.0.0 PHP + WP 3.5+ Updated Apr 20, 2016
contentcustomshortcodeunitswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JKL Unit Converter Safe to Use in 2026?

Generally Safe

Score 85/100

JKL Unit Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "jkl-unit-converter" plugin v1.0.0 exhibits a generally good security posture based on the static analysis provided. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are significant strengths. The presence of a nonce check and a high percentage of properly escaped output further bolster its security. The zero recorded CVEs also suggest a history of responsible development or a lack of past exploitation, which is positive.

However, a notable concern is the lack of capability checks on the single identified shortcode. While the total attack surface is small and there are no unprotected entry points detected at the AJAX or REST API level, the shortcode represents a potential vector for unauthorized actions if it performs sensitive operations. The taint analysis showing zero flows is reassuring, but this could be due to the limited scope of the analysis or the absence of complex data manipulation within the plugin. Overall, the plugin is well-developed from a security perspective, but the missing capability check on the shortcode warrants attention to ensure all potential entry points are adequately secured.

Key Concerns

  • Shortcode without capability check
Vulnerabilities
None known

JKL Unit Converter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JKL Unit Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
23 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped29 total outputs
Attack Surface

JKL Unit Converter Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jkluc] inc\class-jkl-unit-converter-shortcode.php:36
WordPress Hooks 2
actionwidgets_initinc\class-jkl-unit-converter-widget.php:47
actionwp_enqueue_scriptsinc\class-jkl-unit-converter.php:119
Maintenance & Trust

JKL Unit Converter Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 20, 2016
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

JKL Unit Converter Developer Profile

jekkilekki

4 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JKL Unit Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jkl-unit-converter/style.css/wp-content/plugins/jkl-unit-converter/js/functions.js/wp-content/plugins/jkl-unit-converter/js/list-choice.js/wp-content/plugins/jkl-unit-converter/js/list-units.js
Script Paths
/wp-content/plugins/jkl-unit-converter/js/functions.js/wp-content/plugins/jkl-unit-converter/js/list-choice.js/wp-content/plugins/jkl-unit-converter/js/list-units.js
Version Parameters
jkl-unit-converter/style.css?ver=jkl-unit-converter/js/functions.js?ver=jkl-unit-converter/js/list-choice.js?ver=jkl-unit-converter/js/list-units.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- JKL Unit Converter Widget -->
Shortcode Output
[jkluc]
FAQ

Frequently Asked Questions about JKL Unit Converter