SIP Calculator Security & Risk Analysis

wordpress.org/plugins/sip-calculator

SIP Planner & SIP Calculator is a special application that has been deliberately created for all types of users. a housewife, a student, a busines …

200 active installs v1.2 PHP + WP 5.5+ Updated May 26, 2025
calculatorsip-calculator
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 13, 2024
Download
Safety Verdict

Is SIP Calculator Safe to Use in 2026?

Mostly Safe

Score 79/100

SIP Calculator is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 13, 2024Updated 10mo ago
Risk Assessment

The sip-calculator plugin, version 1.2, presents a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found. The plugin also demonstrates good practices in database interaction, with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. There are no identified dangerous functions, file operations, or external HTTP requests in the code.

However, there are significant areas of concern. The absence of nonce checks and capability checks, despite having an entry point (the shortcode), is a notable weakness. This, combined with the historical vulnerability data, points to potential security gaps. The plugin has a known CVE, and importantly, this vulnerability remains unpatched. The fact that the single known vulnerability was a medium-severity Cross-Site Request Forgery (CSRF) and it is still present suggests a pattern of unaddressed security issues.

In conclusion, while the plugin exhibits some good coding practices, the presence of an unpatched medium-severity vulnerability, coupled with the lack of nonce and capability checks on its shortcode entry point, creates a tangible risk. Users should be aware of the potential for CSRF attacks and the need for timely patching when future vulnerabilities are discovered.

Key Concerns

  • Unpatched Medium CVE
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1

SIP Calculator Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12555medium · 6.1Cross-Site Request Forgery (CSRF)

SIP Calculator <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Dec 13, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

SIP Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
197 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped209 total outputs
Attack Surface

SIP Calculator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sip_calculator] frontend\frontend.php:2
WordPress Hooks 3
actionadmin_menubackend\backend.php:3
actionadmin_initbackend\backend.php:124
actionwp_enqueue_scriptssip-calculator.php:17
Maintenance & Trust

SIP Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 26, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

SIP Calculator Developer Profile

mgplugin

10 plugins · 850 total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect SIP Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sip-calculator/frontend/assets/css/rangeslider.min.css/wp-content/plugins/sip-calculator/frontend/assets/css/style.css/wp-content/plugins/sip-calculator/frontend/assets/js/chart.js/wp-content/plugins/sip-calculator/frontend/assets/js/popper.min.js/wp-content/plugins/sip-calculator/frontend/assets/js/rangeSlider.min.js/wp-content/plugins/sip-calculator/frontend/assets/js/sip_calc.js/wp-content/plugins/sip-calculator/frontend/assets/js/sip_calc_front.js
Script Paths
/wp-content/plugins/sip-calculator/frontend/assets/js/sip_calc.js/wp-content/plugins/sip-calculator/frontend/assets/js/sip_calc_front.js/wp-content/plugins/sip-calculator/frontend/assets/js/chart.js/wp-content/plugins/sip-calculator/frontend/assets/js/popper.min.js/wp-content/plugins/sip-calculator/frontend/assets/js/rangeSlider.min.js
Version Parameters
sip-calculator/frontend/assets/css/style.css?ver=sip-calculator/frontend/assets/css/rangeslider.min.css?ver=sip-calculator/frontend/assets/js/sip_calc.js?ver=sip-calculator/frontend/assets/js/sip_calc_front.js?ver=sip-calculator/frontend/assets/js/chart.js?ver=sip-calculator/frontend/assets/js/popper.min.js?ver=sip-calculator/frontend/assets/js/rangeSlider.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
sip-cal-tablesip-result-headsip_label_colorchart_box
Data Attributes
sip_calc_style
JS Globals
sip_calc_style
Shortcode Output
<h1 id="primecap">
FAQ

Frequently Asked Questions about SIP Calculator