NACC WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/nacc-wordpress-plugin

This is a WordPress plugin implementation of the N.A. Cleantime Calculator.

100 active installs v5.1.1 PHP 8.0+ WP 5.3+ Updated Dec 1, 2025
addictioncleantime-calculatornanaccrecovery
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 19, 2024
Safety Verdict

Is NACC WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

NACC WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 19, 2024Updated 4mo ago
Risk Assessment

The nacc-wordpress-plugin v5.1.1 demonstrates strong security practices in its static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping indicate a conscientious approach to preventing common vulnerabilities like SQL injection and cross-site scripting originating from direct code execution or improper data handling. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes, further reduces potential exposure points. However, the plugin has a history of medium-severity vulnerabilities, specifically Cross-Site Scripting, with the last incident occurring recently in December 2024. While currently unpatched CVEs are zero, the past pattern suggests that the plugin might be susceptible to similar injection flaws if not rigorously tested and updated. The lack of nonce and capability checks across its entry points, though seemingly mitigated by the absence of direct vulnerable code paths in the static analysis, could become a concern if functionality changes or new entry points are introduced without adequate authorization checks.

Key Concerns

  • Past medium severity XSS vulnerability
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
Vulnerabilities
1

NACC WordPress Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12506medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NACC WordPress Plugin <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 19, 2024 Patched in 4.2.0 (4d)
Code Analysis
Analyzed Mar 16, 2026

NACC WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped23 total outputs
Attack Surface

NACC WordPress Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nacc] nacc-wordpress-plugin.php:68
WordPress Hooks 8
actioninitnacc-wordpress-plugin.php:48
actionadmin_menunacc-wordpress-plugin.php:63
actionadmin_initnacc-wordpress-plugin.php:64
actionwp_enqueue_scriptsnacc-wordpress-plugin.php:67
filterdo_shortcode_tagnacc-wordpress-plugin.php:69
filterthe_contentnacc-wordpress-plugin.php:70
actionwp_footernacc-wordpress-plugin.php:115
actionwp_footernacc-wordpress-plugin.php:187
Maintenance & Trust

NACC WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version8.0
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

NACC WordPress Plugin Developer Profile

BMLTGuy

2 plugins · 130 total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect NACC WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nacc-wordpress-plugin/dist/css/nacc-styles.css/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js
Script Paths
/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js
Version Parameters
/wp-content/plugins/nacc-wordpress-plugin/dist/css/nacc-styles.css?ver=/wp-content/plugins/nacc-wordpress-plugin/dist/js/nacc.js?ver=

HTML / DOM Fingerprints

CSS Classes
nacc_container
HTML Comments
<!- NACC -><!-- NACC -->
JS Globals
nacc
Shortcode Output
<div id="nacc_container"></div>
FAQ

Frequently Asked Questions about NACC WordPress Plugin