Ultimate Loan & Mortgage Calculator Security & Risk Analysis

wordpress.org/plugins/ultimate-loan-mortgage-calculator

For financial advisors and real estate professionals: the most effective loan & mortgage calculator plugin for WordPress!

100 active installs v1.2.0 PHP 5.6+ WP 4.7+ Updated Feb 25, 2026
amortizationfinanceloan-calculatormortgage-calculatorreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ultimate Loan & Mortgage Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate Loan & Mortgage Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'ultimate-loan-mortgage-calculator' plugin version 1.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in database interaction, using prepared statements exclusively for all SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase regarding external exploits. However, significant concerns arise from its attack surface. A substantial portion of its entry points, specifically all four AJAX handlers, lack authentication checks. This creates a substantial risk of unauthorized access or malicious manipulation of plugin functionalities if these handlers are exploitable. While taint analysis shows no critical or high-severity unsanitized flows, the potential for an attacker to trigger these handlers without proper authorization is a primary security weakness.

Key Concerns

  • 4 AJAX handlers without auth checks
  • 1 File operation detected
  • 2 Nonce checks present, 4 AJAX handlers without
  • 1 Capability check present, 4 AJAX handlers without
Vulnerabilities
None known

Ultimate Loan & Mortgage Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate Loan & Mortgage Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
164 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped171 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_change_color_schema (includes\class-ulmc.php:621)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Ultimate Loan & Mortgage Calculator Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_change_color_schemaincludes\class-ulmc.php:158
noprivwp_ajax_change_color_schemaincludes\class-ulmc.php:159
authwp_ajax_ulmc_send_resultincludes\class-ulmc.php:174
noprivwp_ajax_ulmc_send_resultincludes\class-ulmc.php:175

Shortcodes 1

[ultimate-loan-mortgage-calculator] includes\class-ulmc.php:176
WordPress Hooks 12
actionplugins_loadedincludes\class-ulmc.php:132
actionadmin_initincludes\class-ulmc.php:147
actionadmin_noticesincludes\class-ulmc.php:148
actionadmin_noticesincludes\class-ulmc.php:149
actionadmin_enqueue_scriptsincludes\class-ulmc.php:150
actionadmin_enqueue_scriptsincludes\class-ulmc.php:151
actionadmin_menuincludes\class-ulmc.php:152
actionadmin_initincludes\class-ulmc.php:153
actionadmin_menuincludes\class-ulmc.php:154
actionadmin_footerincludes\class-ulmc.php:156
actionwp_enqueue_scriptsincludes\class-ulmc.php:172
actionwp_enqueue_scriptsincludes\class-ulmc.php:173
Maintenance & Trust

Ultimate Loan & Mortgage Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Ultimate Loan & Mortgage Calculator Developer Profile

THE BELOV

7 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Loan & Mortgage Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-loan-mortgage-calculator/admin/css/ulmc-admin.min.css/wp-content/plugins/ultimate-loan-mortgage-calculator/admin/js/ulmc-vendor.min.js/wp-content/plugins/ultimate-loan-mortgage-calculator/admin/js/ulmc-admin.min.js
Version Parameters
ultimate-loan-mortgage-calculator/admin/css/ulmc-admin.min.css?ver=ultimate-loan-mortgage-calculator/admin/js/ulmc-vendor.min.js?ver=ultimate-loan-mortgage-calculator/admin/js/ulmc-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ulmc-form-groupulmc-form-labelulmc-form-controlulmc-loan-calculator-wrapperulmc-calculator-outputulmc-field-wrap
HTML Comments
<!-- IMPORTANT: Do not edit anything here. The code is auto-generated. --><!-- Default options for the calculator -->
Data Attributes
data-notification_emaildata-primary_colordata-font_sizedata-currencydata-date_formatdata-default_loan_balance+2 more
JS Globals
ulmc_vars
Shortcode Output
[loan_calculator]
FAQ

Frequently Asked Questions about Ultimate Loan & Mortgage Calculator