
NACC WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/nacc-wordpress-pluginThis is a WordPress plugin implementation of the N.A. Cleantime Calculator.
Is NACC WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 99/100NACC WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The nacc-wordpress-plugin v5.1.1 demonstrates strong security practices in its static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping indicate a conscientious approach to preventing common vulnerabilities like SQL injection and cross-site scripting originating from direct code execution or improper data handling. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes, further reduces potential exposure points. However, the plugin has a history of medium-severity vulnerabilities, specifically Cross-Site Scripting, with the last incident occurring recently in December 2024. While currently unpatched CVEs are zero, the past pattern suggests that the plugin might be susceptible to similar injection flaws if not rigorously tested and updated. The lack of nonce and capability checks across its entry points, though seemingly mitigated by the absence of direct vulnerable code paths in the static analysis, could become a concern if functionality changes or new entry points are introduced without adequate authorization checks.
Key Concerns
- Past medium severity XSS vulnerability
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
NACC WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
NACC WordPress Plugin <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
NACC WordPress Plugin Code Analysis
Output Escaping
NACC WordPress Plugin Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
NACC WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
NACC WordPress Plugin Alternatives
Bulk NoIndex & NoFollow Toolkit
bulk-noindex-nofollow-toolkit-by-mad-fish
Bulk set the noindex / nofollow robots tag for posts, pages, categories, and author URLs. Easily identify thin content and noindex it fast.
crouton
crouton
crouton provides a UI and more for view recovery meetings as stored in a Basic Meeting List Toolbox (BMLT) database.
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons
elex-abandoned-cart-recovery-with-dynamic-coupons
Recover abandoned carts with a series of predetermined, rule-based reminder emails that include dynamically generated smart discount coupons.
Publir – Holistic Revenue Engine (HRE)
publir-ump
Seamlessly monetize your WordPress site with optimized ads and premium subscriptions — no code required.
CartResQ – Recover Abandoned Carts for WooCommerce
cartresq
Abandoned cart tracking for WooCommerce. Monitor, analyze, and recover lost sales with real-time detection and analytics.
NACC WordPress Plugin Developer Profile
2 plugins · 130 total installs
How We Detect NACC WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nacc-wordpress-plugin/dist/css/nacc-styles.css/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js/wp-content/plugins/nacc-wordpress-plugin/dist/css/nacc-styles.css?ver=/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js?ver=HTML / DOM Fingerprints
nacc_container<!- NACC -><!-- NACC -->nacc<div id="nacc_container"></div>