Käuferportal Solarrechner-Plugin Security & Risk Analysis

wordpress.org/plugins/kp-solar-rechner

Das Käuferportal Solarrechner-Plugin ermöglicht, einen Solarrechner als Widget oder Shortcode in Deinen Blog zu integrieren.

10 active installs v1.1.0 PHP + WP 2.8+ Updated Jun 6, 2013
calculatorphotovoltaikrechnersolarsolaranlage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Käuferportal Solarrechner-Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Käuferportal Solarrechner-Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "kp-solar-rechner" plugin v1.1.0 presents a generally positive security posture, with no known historical vulnerabilities and a seemingly limited attack surface. The plugin demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no observed file operations or external HTTP requests. The absence of taint analysis findings and known CVEs further contributes to this positive outlook.

However, there are significant areas of concern. The plugin fails to implement any output escaping, meaning that any dynamic data rendered to the user could potentially be exploited. Furthermore, the absence of nonce and capability checks across all entry points is a critical oversight. While the current attack surface is small, these missing security measures leave the plugin vulnerable to various attacks if the attack surface were to expand or if specific attack vectors were identified.

In conclusion, while the plugin has a clean history and avoids common pitfalls like raw SQL and dangerous functions, the lack of output escaping and, more importantly, the complete absence of authorization checks on its single entry point (a shortcode) represent substantial security weaknesses. These are critical deficiencies that significantly increase the risk profile of the plugin.

Key Concerns

  • Output is not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Käuferportal Solarrechner-Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Käuferportal Solarrechner-Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Käuferportal Solarrechner-Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[kp_solar_rechner] kp-solar-rechner.php:93
WordPress Hooks 1
actionwidgets_initkp-solar-rechner.php:91
Maintenance & Trust

Käuferportal Solarrechner-Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJun 6, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Käuferportal Solarrechner-Plugin Developer Profile

kaeuferportal

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Käuferportal Solarrechner-Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kp-solar-rechner/assets/js/kp-solar-rechner.js/wp-content/plugins/kp-solar-rechner/assets/js/solarcalc.js/wp-content/plugins/kp-solar-rechner/assets/css/kp-solar-rechner.css
Script Paths
http://www.kaeuferportal.de/javascripts/jquery.validate.js
Version Parameters
kp-solar-rechner/assets/css/kp-solar-rechner.css?ver=kp-solar-rechner/assets/js/kp-solar-rechner.js?ver=kp-solar-rechner/assets/js/solarcalc.js?ver=

HTML / DOM Fingerprints

CSS Classes
KP_Solar_Rechner_Widget
FAQ

Frequently Asked Questions about Käuferportal Solarrechner-Plugin