
Loan & Mortgage Calculator Pro Security & Risk Analysis
wordpress.org/plugins/loan-mortgage-calculator-proHow Much Will My Monthly Or Daily Mortgage Payments Be? This plugin allows you to calculate your daily loan payments, using New LOC Information, Curre …
Is Loan & Mortgage Calculator Pro Safe to Use in 2026?
Generally Safe
Score 85/100Loan & Mortgage Calculator Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'loan-mortgage-calculator-pro' v1.0.0 reveals a plugin with a very limited attack surface, consisting of a single unprotected shortcode and no other identified entry points. The code also shows good practices in SQL query handling, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a potentially secure offering. However, a significant concern arises from the complete lack of output escaping, meaning any data processed or displayed by the plugin is not sanitized, leaving it vulnerable to cross-site scripting (XSS) attacks. Furthermore, the absence of nonce checks, capability checks, and any form of authentication on the identified entry point is a major security oversight, even though the current static analysis did not identify specific exploitable flows. The lack of any identified dangerous functions or file operations is positive, but the output escaping and lack of authorization checks present critical weaknesses.
Given the clean vulnerability history and the absence of known CVEs, the plugin might appear robust at first glance. However, the static analysis points to fundamental security flaws that could be easily exploited if an attacker can influence the data displayed by the shortcode. The lack of output escaping is a direct pathway to XSS, and the absence of authentication on the shortcode means this risk is accessible to any user. While there are no identified taint flows or SQL injection risks in this specific scan, the lack of proper output handling and authorization significantly elevates the risk profile. The plugin's strength lies in its minimal attack surface and good SQL practices, but its weakness in output sanitization and authorization is a severe concern.
Key Concerns
- Unescaped output
- No capability checks on entry points
- No nonce checks on entry points
Loan & Mortgage Calculator Pro Security Vulnerabilities
Loan & Mortgage Calculator Pro Code Analysis
Output Escaping
Loan & Mortgage Calculator Pro Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Loan & Mortgage Calculator Pro Maintenance & Trust
Maintenance Signals
Community Trust
Loan & Mortgage Calculator Pro Alternatives
Emi Loan Calculator
emi-loan-calculator
Free All Loan Calculator for your Site - Home Loan - Car Loan - Credit Card Car Insurance - Mortgage Calculator - Shortcode [Loan-calculator]
Responsive Mortgage Calculator
responsive-mortgage-calculator
A simple responsive mortgage calculator widget and shortcode.
Mortgage Calculators WP
mortgage-calculators-wp
Mortgage Calculators WP provides users with a simple, elegant and responsive solution for users to calculate mortgage values.
Loan Calculator WP
loan-calculator-wp
Loan / EMI Calculator for Home Loan and Personal Loan
Simple Mortgage Calculator
ct-mortgage-calculator
A straightforward and simple responsive mortgage calculator with a clean flat design.
Loan & Mortgage Calculator Pro Developer Profile
1 plugin · 10 total installs
How We Detect Loan & Mortgage Calculator Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.css/wp-content/plugins/loan-mortgage-calculator-pro/assets/jquery.inputmask.bundle.js/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.js/wp-content/plugins/loan-mortgage-calculator-pro/assets/jquery.inputmask.bundle.js/wp-content/plugins/loan-mortgage-calculator-pro/assets/lmcp-calc.jsHTML / DOM Fingerprints
lmcp-calc[pro-calc]