Widget for My Mitsu Estimation Form Security & Risk Analysis

wordpress.org/plugins/widget-for-my-mitsu-estimation-form

This plugin allows users to put a My Mitsu form in your website's widget area.

10 active installs v1.1 PHP + WP 2.8+ Updated Mar 23, 2017
calculationestimationwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Widget for My Mitsu Estimation Form Safe to Use in 2026?

Generally Safe

Score 85/100

Widget for My Mitsu Estimation Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "widget-for-my-mitsu-estimation-form" plugin v1.1 exhibits a strong security posture based on the provided static analysis. The absence of an attack surface, dangerous functions, raw SQL queries, and external HTTP requests is highly commendable. The plugin also shows good practices in terms of SQL query safety, with 100% of queries using prepared statements. However, a significant concern arises from the low percentage (42%) of properly escaped output. This indicates a potential for cross-site scripting (XSS) vulnerabilities, where untrusted input could be rendered directly in the browser, allowing for malicious code execution.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the limited attack surface and secure coding practices observed in the static analysis, suggests a well-maintained and likely secure plugin. Despite the positive indicators, the unescaped output remains the primary area of concern. While there are no overt critical vulnerabilities detected in the static or taint analysis, the potential for XSS due to insufficient output escaping should not be overlooked. Therefore, while the plugin appears generally secure, addressing the output escaping issue would further strengthen its security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Widget for My Mitsu Estimation Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Widget for My Mitsu Estimation Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped26 total outputs
Attack Surface

Widget for My Mitsu Estimation Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initwidget-my-mitsu.php:12
Maintenance & Trust

Widget for My Mitsu Estimation Form Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMar 23, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Widget for My Mitsu Estimation Form Developer Profile

水野史土

11 plugins · 8K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widget for My Mitsu Estimation Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="mymitsu"id="mymitsu_widget"class="widefat"size="4"id="mymitsu_widget_url"name="mymitsu_widget_url"+6 more
Shortcode Output
<iframesrc="https://my-mitsu.jp/estimation/274"width="320"height="320"
FAQ

Frequently Asked Questions about Widget for My Mitsu Estimation Form