Loan & Mortgage Calculator Pro Security & Risk Analysis

wordpress.org/plugins/loan-mortgage-calculator-pro

How Much Will My Monthly Or Daily Mortgage Payments Be? This plugin allows you to calculate your daily loan payments, using New LOC Information, Curre …

10 active installs v1.0.0 PHP + WP 4.0+ Updated Feb 8, 2019
calculatorhome-loan-calculatorloan-calculatormortgage-calculatorpayoff-date-calculator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Loan & Mortgage Calculator Pro Safe to Use in 2026?

Generally Safe

Score 85/100

Loan & Mortgage Calculator Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of 'loan-mortgage-calculator-pro' v1.0.0 reveals a plugin with a very limited attack surface, consisting of a single unprotected shortcode and no other identified entry points. The code also shows good practices in SQL query handling, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a potentially secure offering. However, a significant concern arises from the complete lack of output escaping, meaning any data processed or displayed by the plugin is not sanitized, leaving it vulnerable to cross-site scripting (XSS) attacks. Furthermore, the absence of nonce checks, capability checks, and any form of authentication on the identified entry point is a major security oversight, even though the current static analysis did not identify specific exploitable flows. The lack of any identified dangerous functions or file operations is positive, but the output escaping and lack of authorization checks present critical weaknesses.

Given the clean vulnerability history and the absence of known CVEs, the plugin might appear robust at first glance. However, the static analysis points to fundamental security flaws that could be easily exploited if an attacker can influence the data displayed by the shortcode. The lack of output escaping is a direct pathway to XSS, and the absence of authentication on the shortcode means this risk is accessible to any user. While there are no identified taint flows or SQL injection risks in this specific scan, the lack of proper output handling and authorization significantly elevates the risk profile. The plugin's strength lies in its minimal attack surface and good SQL practices, but its weakness in output sanitization and authorization is a severe concern.

Key Concerns

  • Unescaped output
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Loan & Mortgage Calculator Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Loan & Mortgage Calculator Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Loan & Mortgage Calculator Pro Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pro-calc] class.lmcpcalc.php:16
WordPress Hooks 2
actionwp_enqueue_scriptsclass.lmcpcalc.php:15
actioninitlmcpcalc.php:17
Maintenance & Trust

Loan & Mortgage Calculator Pro Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 8, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Loan & Mortgage Calculator Pro Developer Profile

Sarbjit Singh Grewal

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Loan & Mortgage Calculator Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.css/wp-content/plugins/loan-mortgage-calculator-pro/assets/jquery.inputmask.bundle.js/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.js
Script Paths
/wp-content/plugins/loan-mortgage-calculator-pro/assets/jquery.inputmask.bundle.js/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.js

HTML / DOM Fingerprints

CSS Classes
lmcp-calc
Shortcode Output
[pro-calc]
FAQ

Frequently Asked Questions about Loan & Mortgage Calculator Pro