Property Hive Mortgage Calculator Security & Risk Analysis

wordpress.org/plugins/property-hive-mortgage-calculator

Quickly and easily add a mortgage calculator to your website

800 active installs v1.0.7 PHP + WP 3.8+ Updated Dec 4, 2024
mortgagemortgage-calculatorproperty-hivepropertyhiverepayments
91
A · Safe
CVEs total1
Unpatched0
Last CVEDec 9, 2024
Safety Verdict

Is Property Hive Mortgage Calculator Safe to Use in 2026?

Generally Safe

Score 91/100

Property Hive Mortgage Calculator has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 9, 2024Updated 1yr ago
Risk Assessment

The security posture of the property-hive-mortgage-calculator plugin version 1.0.7 appears to be generally good based on the static analysis. The absence of dangerous functions, properly escaped output, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, there are no identified taint flows or flows with unsanitized paths, suggesting the code does not exhibit common vulnerability patterns related to input handling. The plugin also boasts a minimal attack surface with only one shortcode and no unprotected entry points identified during the static analysis.

However, a notable concern arises from the vulnerability history, which indicates one known medium-severity CVE related to Cross-Site Scripting (XSS). While this vulnerability is listed as currently unpatched, its age (2024-12-09) might suggest it has been fixed in subsequent versions, though this is not explicitly confirmed by the provided data. The complete lack of nonce checks and capability checks across all identified entry points is a significant weakness. This means that even though the code itself appears to handle data safely, there are no built-in mechanisms to prevent unauthorized users from triggering these functions, potentially leading to unintended actions or the exploitation of other vulnerabilities if they were to be discovered in the future.

In conclusion, the plugin demonstrates strong adherence to secure coding practices concerning SQL and output handling. The static analysis reveals a clean codebase with a small attack surface. The primary weakness lies in the absence of authorization checks (nonces and capabilities) on its entry points, which leaves it susceptible to abuse if an attacker can bypass frontend restrictions. The past XSS vulnerability, while seemingly resolved, highlights the importance of ongoing security vigilance and prompt patching of any disclosed issues.

Key Concerns

  • One medium severity CVE history
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
Vulnerabilities
1

Property Hive Mortgage Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11940medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Property Hive Mortgage Calculator <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via price Parameter

Dec 9, 2024 Patched in 1.0.7 (1d)
Code Analysis
Analyzed Mar 16, 2026

Property Hive Mortgage Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped23 total outputs
Attack Surface

Property Hive Mortgage Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mortgage_calculator] propertyhive-mortgage-calculator.php:71
WordPress Hooks 2
actionwp_enqueue_scriptspropertyhive-mortgage-calculator.php:68
actionwp_enqueue_scriptspropertyhive-mortgage-calculator.php:69
Maintenance & Trust

Property Hive Mortgage Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 4, 2024
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

Property Hive Mortgage Calculator Developer Profile

Property Hive

8 plugins · 7K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
218 days
View full developer profile
Detection Fingerprints

How We Detect Property Hive Mortgage Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/property-hive-mortgage-calculator/assets/js/propertyhive-mortgage-calculator.js/wp-content/plugins/property-hive-mortgage-calculator/assets/css/propertyhive-mortgage-calculator.css
Script Paths
/wp-content/plugins/property-hive-mortgage-calculator/assets/js/propertyhive-mortgage-calculator.js
Version Parameters
property-hive-mortgage-calculator/assets/js/propertyhive-mortgage-calculator.js?ver=property-hive-mortgage-calculator/assets/css/propertyhive-mortgage-calculator.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Property Hive Mortgage Calculator