Property Hive Stamp Duty Calculator Security & Risk Analysis

wordpress.org/plugins/property-hive-stamp-duty-calculator

Quickly and easily add a stamp duty calculator to your website.

900 active installs v1.0.28 PHP + WP 3.8+ Updated Feb 11, 2026
property-hivepropertyhivestamp-dutystamp-duty-calculatorstampduty
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 12, 2024
Safety Verdict

Is Property Hive Stamp Duty Calculator Safe to Use in 2026?

Generally Safe

Score 99/100

Property Hive Stamp Duty Calculator has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 12, 2024Updated 1mo ago
Risk Assessment

The property-hive-stamp-duty-calculator plugin version 1.0.28 exhibits a mixed security posture. On the positive side, the code does not utilize dangerous functions, all SQL queries are properly prepared, and there are no direct file operations or external HTTP requests, which are good security practices. The absence of taint analysis findings and zero unprotected entry points also suggest a level of diligence in sanitizing inputs and controlling access.

However, significant concerns arise from the lack of any capability checks or nonce checks. This means that even though the entry points are not exposed without authentication, the internal handling of these entry points might be vulnerable if an attacker can bypass or manipulate the user's session. The low percentage of properly escaped output (20%) is a critical weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, which aligns with its vulnerability history.

The plugin has a history of a known CVE, specifically related to Cross-Site Scripting, although it is currently patched. The presence of past XSS vulnerabilities, coupled with the low output escaping rate in static analysis, strongly suggests that XSS remains a persistent risk. While the current version may have fixed past CVEs, the underlying code practices regarding output sanitization are a major concern, leaving it susceptible to new XSS exploits.

Key Concerns

  • Low output escaping percentage (20%)
  • No nonce checks implemented
  • No capability checks implemented
  • History of Cross-Site Scripting vulnerabilities
Vulnerabilities
1

Property Hive Stamp Duty Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12465medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Property Hive Stamp Duty Calculator <= 1.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2024 Patched in 1.0.23 (1d)
Code Analysis
Analyzed Mar 16, 2026

Property Hive Stamp Duty Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped20 total outputs
Attack Surface

Property Hive Stamp Duty Calculator Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[stamp_duty_calculator] propertyhive-stamp-duty-calculator.php:71
[stamp_duty_calculator_scotland] propertyhive-stamp-duty-calculator.php:73
[stamp_duty_calculator_commercial] propertyhive-stamp-duty-calculator.php:75
[stamp_duty_calculator_wales] propertyhive-stamp-duty-calculator.php:77
WordPress Hooks 2
actionwp_enqueue_scriptspropertyhive-stamp-duty-calculator.php:68
actionwp_enqueue_scriptspropertyhive-stamp-duty-calculator.php:69
Maintenance & Trust

Property Hive Stamp Duty Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version
Downloads20K

Community Trust

Rating76/100
Number of ratings5
Active installs900
Developer Profile

Property Hive Stamp Duty Calculator Developer Profile

Property Hive

8 plugins · 7K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
218 days
View full developer profile
Detection Fingerprints

How We Detect Property Hive Stamp Duty Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator.js/wp-content/plugins/property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-scotland.js/wp-content/plugins/property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-commercial.js/wp-content/plugins/property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-wales.js/wp-content/plugins/property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator.css/wp-content/plugins/property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-scotland.css/wp-content/plugins/property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-commercial.css/wp-content/plugins/property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-wales.css
Version Parameters
property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator.js?ver=property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-scotland.js?ver=property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-commercial.js?ver=property-hive-stamp-duty-calculator/assets/js/propertyhive-stamp-duty-calculator-wales.js?ver=property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator.css?ver=property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-scotland.css?ver=property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-commercial.css?ver=property-hive-stamp-duty-calculator/assets/css/propertyhive-stamp-duty-calculator-wales.css?ver=

HTML / DOM Fingerprints

Shortcode Output
[stamp_duty_calculator][stamp_duty_calculator_scotland][stamp_duty_calculator_commercial][stamp_duty_calculator_wales]
FAQ

Frequently Asked Questions about Property Hive Stamp Duty Calculator