
Power Calculator Security & Risk Analysis
wordpress.org/plugins/power-calculatorA single shortcode insert and turn your page or post into Power Calculator and calculate power load, inverter size and solar panel size
Is Power Calculator Safe to Use in 2026?
Generally Safe
Score 85/100Power Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "power-calculator" v1.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, SQL queries executed with prepared statements, and file operations is a strong indicator of good coding practices. The high percentage of properly escaped output further contributes to a robust defense against common web vulnerabilities like Cross-Site Scripting (XSS). The plugin also has no recorded vulnerability history, suggesting a history of secure development or a lack of prior extensive security auditing.
However, the analysis reveals several potential areas of concern that prevent a perfect score. The most significant is the complete lack of nonce checks and capability checks. While the attack surface is currently small and all identified entry points are technically protected (0 unprotected), the absence of these fundamental WordPress security mechanisms means that an attacker could potentially trigger actions or access data if they can find a way to call the shortcode without proper authorization. This is a significant oversight in a WordPress context, as these checks are crucial for preventing unauthorized access and actions.
In conclusion, the plugin demonstrates good practices in handling data and queries, but its security is significantly weakened by the omission of essential WordPress authorization and noncing mechanisms. The lack of vulnerability history is a positive sign, but it does not negate the risks introduced by the missing security controls. Addressing the absence of nonce and capability checks would drastically improve the plugin's overall security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- 1 entry point (shortcode) without auth checks
- 12% unescaped output
Power Calculator Security Vulnerabilities
Power Calculator Code Analysis
Output Escaping
Power Calculator Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Power Calculator Maintenance & Trust
Maintenance Signals
Community Trust
Power Calculator Alternatives
No alternatives data available yet.
Power Calculator Developer Profile
2 plugins · 20 total installs
How We Detect Power Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/power-calculator/assets/css/main-style.css/wp-content/plugins/power-calculator/assets/js/main.js/wp-content/plugins/power-calculator/assets/js/vue.js/wp-content/plugins/power-calculator/assets/js/vue-loader.js/wp-content/plugins/power-calculator/assets/js/main.js/wp-content/plugins/power-calculator/assets/js/vue.js/wp-content/plugins/power-calculator/assets/js/vue-loader.js/wp-content/plugins/power-calculator/assets/css/main-style.css?ver=/wp-content/plugins/power-calculator/assets/js/main.js?ver=/wp-content/plugins/power-calculator/assets/js/vue.js?ver=/wp-content/plugins/power-calculator/assets/js/vue-loader.js?ver=HTML / DOM Fingerprints
window.power_handle[power-calculator]