Simple Price Calculator Security & Risk Analysis

wordpress.org/plugins/simple-price-calculator-basic

Simple Price Calculator is a WordPress plugin that can transform any html based form into a price calculation form. You can

40 active installs v1.3 PHP + WP 3.8+ Updated Mar 16, 2018
calculatororder-formprice-calculatorprice-calculator-formquote-form
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is Simple Price Calculator Safe to Use in 2026?

Use With Caution

Score 63/100

Simple Price Calculator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 8yr ago
Risk Assessment

The plugin exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests. This indicates a good effort to avoid common web vulnerabilities. However, there are significant concerns regarding output escaping, with only 33% of outputs properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks across all entry points, including the single shortcode, is a major weakness, leaving the plugin highly susceptible to Cross-Site Request Forgery (CSRF) attacks. The vulnerability history reveals a past medium-severity vulnerability of "Missing Authorization", which aligns with the current lack of capability checks. The presence of a currently unpatched medium-severity CVE from September 2025 is a critical concern, highlighting an ongoing risk. While some code practices are strong, the lack of authorization and nonce checks, coupled with unpatched vulnerabilities and poor output escaping, present a substantial security risk.

Key Concerns

  • Currently unpatched CVE: Medium Severity
  • Output escaping: 67% not properly escaped
  • Nonce checks: 0 found
  • Capability checks: 0 found
  • Vulnerability history: Missing Authorization
Vulnerabilities
1 published

Simple Price Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58872medium · 4.3Missing Authorization

Simple Price Calculator <= 1.3 - Missing Authorization

Sep 5, 2025Unpatched
Version History

Simple Price Calculator Release Timeline

v1.3Current1 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Simple Price Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

Simple Price Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[spc-form] simplepricecalc.php:23
WordPress Hooks 8
actioninitsimplepricecalc.php:22
actioninitspcadmin.php:9
actionadmin_initspcadmin.php:10
filtermanage_edit-simple_price_calc_columnsspcadmin.php:11
actionmanage_simple_price_calc_posts_custom_columnspcadmin.php:12
actionedit_form_after_titlespcadmin.php:13
filterpost_updated_messagesspcadmin.php:14
actionadmin_menuspcadmin.php:15
Maintenance & Trust

Simple Price Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 16, 2018
PHP min version
Downloads14K

Community Trust

Rating68/100
Number of ratings8
Active installs40
Developer Profile

Simple Price Calculator Developer Profile

premiumbizthemes

1 plugin · 40 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Price Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-price-calculator-basic/spcstyle.css/wp-content/plugins/simple-price-calculator-basic/simplepricecalc.min.js/wp-content/plugins/simple-price-calculator-basic/jquery.number.min.js
Script Paths
jquery.number.min.jssimplepricecalc.min.js
Version Parameters
simple-price-calculator-basic/spcstyle.css?ver=simple-price-calculator-basic/simplepricecalc.min.js?ver=simple-price-calculator-basic/jquery.number.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
spcrowspc-admin-panel
HTML Comments
HTML Code For Form tag generator Functions below available in premium version. Copy this code below and place in editor Admin Panel Functions+6 more
Data Attributes
data-spc-id
JS Globals
jQuery$
Shortcode Output
[spc-form id=<form id="spcquoteform">
FAQ

Frequently Asked Questions about Simple Price Calculator