PS4L Pond Calculator Security & Risk Analysis

wordpress.org/plugins/ps4l-pond-calculator

Donate link: https://pondsuppliesforless.com/pages/resources Tags: pond calculator, ponds, gardening, home improvement, pond tools, pond scripts, pon …

0 active installs v1.0.0 PHP + WP + Updated Jan 15, 2018
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PS4L Pond Calculator Safe to Use in 2026?

Generally Safe

Score 85/100

PS4L Pond Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'ps4l-pond-calculator' v1.0.0 plugin exhibits a generally positive security posture based on the static analysis provided. The absence of known CVEs and the complete lack of taint analysis findings, along with no dangerous functions or file operations, are strong indicators of a well-developed and secure plugin. The plugin also demonstrates good practice by not making external HTTP requests, which can be a common attack vector. However, there are notable areas for improvement that introduce potential risks. The most significant concern is the extremely low rate of proper output escaping (27%), which leaves the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is rendered directly into the HTML without adequate sanitization. Additionally, the lack of nonce and capability checks on the single shortcode, while not directly flagged as an unprotected entry point in this specific analysis, could still allow for unauthorized actions or unexpected behavior if the shortcode's functionality is not inherently benign. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of responsible development, but it does not negate the immediate risks identified in the current code.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

PS4L Pond Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PS4L Pond Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped74 total outputs
Attack Surface

PS4L Pond Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pondcalculator] pond-calculator.php:211
WordPress Hooks 3
actionwidgets_initpond-calculator.php:27
actionadmin_enqueue_scriptspond-calculator.php:28
actionwp_enqueue_scriptspond-calculator.php:30
Maintenance & Trust

PS4L Pond Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 15, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

PS4L Pond Calculator Alternatives

No alternatives data available yet.

Developer Profile

PS4L Pond Calculator Developer Profile

sellersbay

2 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PS4L Pond Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ps4l-pond-calculator/css/style.css/wp-content/plugins/ps4l-pond-calculator/css/bootstrap.css/wp-content/plugins/ps4l-pond-calculator/css/bootstrap.min.css/wp-content/plugins/ps4l-pond-calculator/js/pond.js/wp-content/plugins/ps4l-pond-calculator/js/bootstrap.min.js/wp-content/plugins/ps4l-pond-calculator/js/bootstrap.js/wp-content/plugins/ps4l-pond-calculator/js/accounting.js/wp-content/plugins/ps4l-pond-calculator/js/colorpicker.js
Script Paths
/wp-content/plugins/ps4l-pond-calculator/js/colorpicker.js/wp-content/plugins/ps4l-pond-calculator/js/pond.js/wp-content/plugins/ps4l-pond-calculator/js/bootstrap.min.js/wp-content/plugins/ps4l-pond-calculator/js/bootstrap.js/wp-content/plugins/ps4l-pond-calculator/js/accounting.js

HTML / DOM Fingerprints

CSS Classes
desktop-pondmain-pondselect-pond-mainthree-shapescolor-icon-greenmain-formpondl1pondw1+8 more
Data Attributes
rel="popuprel2"
JS Globals
WSGTWS_Pond_CalculatornumonlyGetresultsGetresultsoval
Shortcode Output
<div class="desktop-pond"><div class="main-pond"><div class="select-pond-main"<h3
FAQ

Frequently Asked Questions about PS4L Pond Calculator