Website Carbon Calculator Security & Risk Analysis

wordpress.org/plugins/website-carbon-calculator

Effortlessly calculate any page’s impact and performance, with real-time results and no reliance on the Website Carbon API, ensuring instant updates.

20 active installs v1.3.8 PHP 7.1+ WP 5.8+ Updated Dec 1, 2025
carbonemissionsmeasureperformancesustainability
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Website Carbon Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

Website Carbon Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The website-carbon-calculator plugin version 1.3.8 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent adherence to secure coding practices, with all SQL queries using prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and critical/high severity taint flows further enhances its security. The limited attack surface, consisting of only three AJAX handlers, is also a positive indicator, although the lack of explicit capability checks on these handlers represents a minor concern.

Furthermore, the plugin's vulnerability history is entirely clean, with no recorded CVEs of any severity. This indicates a history of secure development and maintenance. The presence of only one external HTTP request is a minimal risk. The plugin's reliance on the Guzzle library is noted but does not present an immediate concern without further analysis of its specific version and potential vulnerabilities within that bundled library.

In conclusion, the website-carbon-calculator plugin appears to be a very secure option. Its strengths lie in its robust use of prepared statements, proper output escaping, and a clean vulnerability record. The primary area for potential improvement would be to implement capability checks on the AJAX handlers to further harden the plugin against unauthorized access, although the current lack of explicit checks combined with the absence of other vulnerabilities does not present an immediate critical threat.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

Website Carbon Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Website Carbon Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
0
155 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared12 total queries

Output Escaping

100% escaped155 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
carbon_calculate (includes\actions.php:229)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Website Carbon Calculator Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_carbon_calculateincludes\actions.php:39
authwp_ajax_reset_carbon_calculationincludes\actions.php:40
authwp_ajax_get_calculated_carbonincludes\actions.php:41
WordPress Hooks 13
actionpassword_protected_is_activeincludes\actions.php:11
action_wp_put_post_revisionincludes\actions.php:12
filterposts_resultsincludes\actions.php:13
actionadd_meta_boxesincludes\actions.php:23
actionwp_dashboard_setupincludes\dashboard.php:13
actionadmin_headincludes\main.php:19
actionadmin_noticesincludes\migration.php:7
actionadmin_initincludes\migration.php:9
actionadmin_menuincludes\settings.php:11
actionadmin_initincludes\settings.php:12
actionadmin_noticesincludes\settings.php:50
actionadmin_menuincludes\tools.php:14
actionplugins_loadedwebsite-carbon-calculator.php:40
Maintenance & Trust

Website Carbon Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 1, 2025
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Website Carbon Calculator Developer Profile

Sustainable Web Dev

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Website Carbon Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/website-carbon-calculator/public/script.js/wp-content/plugins/website-carbon-calculator/public/style.css
Script Paths
/wp-content/plugins/website-carbon-calculator/public/script.js
Version Parameters
website-carbon-calculator/public/script.js?ver=website-carbon-calculator/public/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpcc-iconwpcc-badgewpcc-badge--greywpcc-performancewpcc-performance--grey
Data Attributes
data-ajax_urldata-reference
JS Globals
website_carbon_calculator
REST Endpoints
/wp-json/wpcc/v1/calculate
FAQ

Frequently Asked Questions about Website Carbon Calculator