Shortcode for My Mitsu Estimation Form Security & Risk Analysis

wordpress.org/plugins/shortcode-for-my-mitsu-estimation-form

This plugin allows users to put a My Mitsu estimation form in your website.

30 active installs v1.3 PHP + WP 2.5+ Updated Aug 3, 2019
calculationcalculatorestimationformshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shortcode for My Mitsu Estimation Form Safe to Use in 2026?

Generally Safe

Score 85/100

Shortcode for My Mitsu Estimation Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "shortcode-for-my-mitsu-estimation-form" plugin version 1.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, proper use of prepared statements for all SQL queries, and complete output escaping are excellent indicators of secure coding practices. The limited attack surface, consisting of a single shortcode with a capability check, further reduces the potential for exploits. The plugin also has no recorded vulnerabilities, which suggests a history of secure development or diligent maintenance.

However, the lack of nonce checks is a notable concern. While the static analysis reports no unsanitized taint flows and all outputs are escaped, the absence of nonces on the shortcode means that an attacker could potentially trigger the shortcode's functionality repeatedly or in unintended ways without proper validation. This could lead to denial-of-service or other issues depending on the shortcode's specific implementation, though the analysis doesn't indicate any directly exploitable vulnerabilities in this regard. The plugin also has no AJAX handlers or REST API routes, which, while contributing to a small attack surface, also means these potential entry points are not being secured or tested.

Overall, the plugin demonstrates a good foundation in security by avoiding common pitfalls like raw SQL and unescaped output. The primary area for improvement lies in implementing nonce checks to prevent potential abuse of the shortcode functionality. The clean vulnerability history is a positive sign, but it's important to maintain vigilance and continue following secure coding practices.

Key Concerns

  • Shortcodes lack nonce checks
Vulnerabilities
None known

Shortcode for My Mitsu Estimation Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shortcode for My Mitsu Estimation Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Shortcode for My Mitsu Estimation Form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mymitsu] mymitsuphp.php:54
WordPress Hooks 2
actionplugins_loadedmymitsuphp.php:17
actionadmin_menumymitsuphp.php:60
Maintenance & Trust

Shortcode for My Mitsu Estimation Form Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 3, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Shortcode for My Mitsu Estimation Form Developer Profile

水野史土

11 plugins · 8K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shortcode for My Mitsu Estimation Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<iframe src="https://my-mitsu.jp/estimation/274" id="mymitsu" width="640" height="480"></iframe><iframe src="https://my-mitsu.jp/estimation/<iframe src="https://my-mitsu.jp/estimation/id="mymitsu"
FAQ

Frequently Asked Questions about Shortcode for My Mitsu Estimation Form