
Solar Wizard Lite Security & Risk Analysis
wordpress.org/plugins/solar-wizard-liteThe first solar power calculator for Wordpress websites. If you're tired of answering the questions" how much does it cost to go solar?
Is Solar Wizard Lite Safe to Use in 2026?
Generally Safe
Score 91/100Solar Wizard Lite has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The solar-wizard-lite plugin v1.2.5 exhibits a concerning security posture primarily due to a large attack surface with a significant number of unprotected entry points. While the plugin demonstrates good practices in SQL query handling and shows a high percentage of properly escaped output, the presence of 8 AJAX handlers without any authentication checks is a critical weakness. This could allow unauthenticated users to trigger potentially sensitive actions or expose information. The taint analysis, while limited in scope, identified two flows with unsanitized paths, which, although not classified as critical or high, warrant attention. The vulnerability history indicates a past XSS vulnerability, and the recent date of the last vulnerability suggests the plugin is actively maintained but has had security flaws. Overall, the plugin has strengths in SQL and output escaping but significant risks due to unprotected AJAX endpoints and potential path sanitization issues.
Key Concerns
- 8 unprotected AJAX handlers
- 2 flows with unsanitized paths
- 1 known CVE in vulnerability history
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- 25% of outputs not properly escaped
Solar Wizard Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Solar Wizard Lite <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Solar Wizard Lite Release Timeline
Solar Wizard Lite Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Solar Wizard Lite Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Solar Wizard Lite Maintenance & Trust
Maintenance Signals
Community Trust
Solar Wizard Lite Alternatives
Solar Calculator
solar-calculator
A modern, user-friendly WordPress plugin designed to promote solar energy, calculate the potential solar power generation at a specific location.
SyntaxHighlighter Evolved Themes
syntaxhighlighter-evolved-themes
Adds new themes to the SyntaxHighlighter Evolved plugin.
Power Calculator
power-calculator
A single shortcode insert and turn your page or post into Power Calculator and calculate power load, inverter size and solar panel size
Helioviewer.org – Latest Image
helioviewerorg-latest-image-of-the-sun
Displays the latest image of the Sun from Helioviewer.org.
Käuferportal Solarrechner-Plugin
kp-solar-rechner
Das Käuferportal Solarrechner-Plugin ermöglicht, einen Solarrechner als Widget oder Shortcode in Deinen Blog zu integrieren.
Solar Wizard Lite Developer Profile
1 plugin · 200 total installs
How We Detect Solar Wizard Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/solar-wizard-lite/css/solar-wizard-style.css/wp-content/plugins/solar-wizard-lite/js/solar-wizard.js/wp-content/plugins/solar-wizard-lite/js/solar-wizard.jssolar-wizard-lite/css/solar-wizard-style.css?ver=solar-wizard-lite/js/solar-wizard.js?ver=HTML / DOM Fingerprints
solwzd-review-btnSolar Calculator is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 2 of the License, or
any later version.Solar Calculator is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.You should have received a copy of the GNU General Public License
along with Solar Calculator. If not, see {URI to Plugin License}.data-tab=solwzd_ajax_object/wp-json/solwzd/v1/submit/wp-json/solwzd/v1/calculate[solar_wizard]