Nationwide Auto-Transportation Quote Calculator Security & Risk Analysis

wordpress.org/plugins/nationwide-auto-transportation-quote-calculator

Quote Calculator Plugin for Getting Free Quotes from Nationwide Auto-Transportation

10 active installs v1.0 PHP + WP 2.9.0+ Updated Unknown
auto-shipping-calculatorcar-shipping-calculatorvehicle-shipping-calculator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nationwide Auto-Transportation Quote Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

Nationwide Auto-Transportation Quote Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "nationwide-auto-transportation-quote-calculator" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and the developer's apparent adherence to secure coding practices, such as utilizing prepared statements for all SQL queries and almost universally escaping output, are significant positive indicators. The limited attack surface, consisting of a single shortcode with no apparent access controls, also suggests a low risk of direct exploitation through common WordPress entry points.

However, there are areas of concern that warrant attention. The presence of two taint flows with unsanitized paths, despite no critical or high severity being flagged, indicates potential for attackers to manipulate data inputs if not handled carefully within the shortcode's logic. Furthermore, the lack of any nonce checks or capability checks, particularly for the shortcode which represents the sole entry point, is a notable weakness. This means that any user, regardless of their logged-in status or privileges, could potentially trigger the shortcode's functionality, opening the door for Cross-Site Request Forgery (CSRF) or other unintended executions if the shortcode performs sensitive actions.

In conclusion, while the plugin demonstrates good practices in database and output handling and has a clean vulnerability history, the absence of authentication and authorization checks on its sole entry point, coupled with the identified unsanitized taint flows, presents a tangible risk. Addressing these specific security gaps should be a priority to further harden the plugin.

Key Concerns

  • Unsanitized taint flows detected
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Nationwide Auto-Transportation Quote Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nationwide Auto-Transportation Quote Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
69 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped73 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
nat_qc_getQuoteForData (functions.php:163)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Nationwide Auto-Transportation Quote Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nat-quote-calculator] functions.php:463
WordPress Hooks 1
actionadmin_menunat-quote-calculator.php:15
Maintenance & Trust

Nationwide Auto-Transportation Quote Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

Nationwide Auto-Transportation Quote Calculator Alternatives

No alternatives data available yet.

Developer Profile

Nationwide Auto-Transportation Quote Calculator Developer Profile

nationwideautotransport

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nationwide Auto-Transportation Quote Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nationwide-auto-transportation-quote-calculator/css/admin-page.css/wp-content/plugins/nationwide-auto-transportation-quote-calculator/js/admin-page.js
Version Parameters
nationwide-auto-transportation-quote-calculator/css/admin-page.css?ver=nationwide-auto-transportation-quote-calculator/js/admin-page.js?ver=

HTML / DOM Fingerprints

CSS Classes
input-container
Data Attributes
id="title"id="main-color"id="secondary-color"id="submit-bg"id="submit-color"id="submit-hover-bg"+9 more
JS Globals
window.nat_qc_quoteCalculator
Shortcode Output
[nat-quote-caclculator]
FAQ

Frequently Asked Questions about Nationwide Auto-Transportation Quote Calculator