
Simple Finance Calculator Security & Risk Analysis
wordpress.org/plugins/simple-finance-calculatorCreates a very simple form that can be used to calculate monthly payments or loan amount based on entered information.
Is Simple Finance Calculator Safe to Use in 2026?
Use With Caution
Score 63/100Simple Finance Calculator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The simple-finance-calculator plugin version 1.0 presents a mixed security posture. While it demonstrates good practices in its handling of SQL queries with prepared statements and appears to have a limited attack surface with no unprotected entry points identified in the static analysis, several concerning signals are present. The use of the `create_function` is a significant red flag, as it is deprecated and can be a source of vulnerabilities if not handled with extreme care, often leading to code injection. Furthermore, the low percentage of properly escaped output (22%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by other users.
The vulnerability history further amplifies these concerns. The presence of a known medium severity CVE, which is currently unpatched, directly points to a past XSS vulnerability. This history, coupled with the static analysis findings regarding output escaping and the use of `create_function`, indicates a pattern of potential insecurity. While the plugin has strengths in its structured data handling, the identified risks related to code execution and unescaped output, compounded by an unpatched historical vulnerability, necessitate a cautious approach. Users should be aware of the potential for XSS and the risks associated with the deprecated `create_function` until these issues are addressed.
Key Concerns
- Unpatched CVE
- Use of dangerous function (create_function)
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Simple Finance Calculator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Finance Calculator <= 1.0 - Reflected Cross-Site Scripting
Simple Finance Calculator Code Analysis
Dangerous Functions Found
Output Escaping
Simple Finance Calculator Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Simple Finance Calculator Maintenance & Trust
Maintenance Signals
Community Trust
Simple Finance Calculator Alternatives
Investment Decision Helper
investment-decision-helper
This tool will allow you to compare return rates of two different custom instruments in order to help you taking the best decision..
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
CC Canadian Mortgage Calculator
cc-canadian-mortgage-calculator
Add a free simple customizable Canadian mortgage calculator to your web site.
Simple Pregnancy Calculator
simple-pregnancy-calculator
Simple Pregnancy Calculator lets you add a datepicher in the page or in the widget area of your site.
Simple Loan and Mortgage Calculator
simple-loan-mortgage-calculator
Simple Loan and Mortgage Calculator generates a report on the payment of any loan or mortgage.
Simple Finance Calculator Developer Profile
2 plugins · 90 total installs
How We Detect Simple Finance Calculator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-finance-calculator/simple-finance-calculator.cssHTML / DOM Fingerprints
sfc_calculatorsfc_validation_errorsfc_erroranpseparatorsfc_resultsname="r"name="n"name="a"name="payment"<form class="sfc_calculator" method="post"><p class="sfc_validation_error"><p class="sfc_error"><div class="anp">