TaxCaster Security & Risk Analysis

wordpress.org/plugins/taxcaster

Provides the TaxCaster Lite tax calculator application on any post or page in WordPress

10 active installs v2.0 PHP + WP 3.0+ Updated Jan 23, 2012
estimate-tax-refundtax-calculatortax-estimatorturbo-taxturbotax
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TaxCaster Safe to Use in 2026?

Generally Safe

Score 85/100

TaxCaster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the Taxcaster plugin v2.0 exhibits a strong security posture. The static analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Crucially, there are no identified taint flows, indicating no pathways for unsanitized data to be processed in a potentially harmful way. The plugin also demonstrates good practices by having zero external HTTP requests and no file operations, further reducing its attack surface. The complete absence of known CVEs and historical vulnerabilities is a significant strength, suggesting a well-maintained and secure codebase. However, the analysis does note zero nonce checks and zero capability checks. While the limited attack surface (one shortcode) might mitigate immediate risks, these omissions represent potential points of weakness if the plugin's functionality were to evolve or if new attack vectors emerge that target these specific areas. Overall, Taxcaster v2.0 appears to be a secure plugin with minimal inherent risks, but the lack of robust authentication and authorization mechanisms on its entry points warrants attention.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

TaxCaster Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TaxCaster Release Timeline

v2.0.0.0
v1.2.0.0
v1.1.0.0
v1.0.0.0
Code Analysis
Analyzed Apr 16, 2026

TaxCaster Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

TaxCaster Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[taxcaster] taxcaster.php:51
WordPress Hooks 1
actionadmin_menutaxcaster.php:30
Maintenance & Trust

TaxCaster Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedJan 23, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

TaxCaster Developer Profile

Brad Williams

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TaxCaster

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/taxcaster/includes/EightQuestionRefundEstimator.swf

HTML / DOM Fingerprints

CSS Classes
wrapicon32
Shortcode Output
<object width="450" height="550"><param name="movie" value="<embed src="Powered by <a href="http://turbotax.intuit.com/tax-tools/calculators/taxcaster/">Taxcaster Tax Refund Calculator</a>
FAQ

Frequently Asked Questions about TaxCaster