
WM JqMath Security & Risk Analysis
wordpress.org/plugins/wm-jqmathCreate math formulas on your posts and pages using jqMath from MathScribe
Is WM JqMath Safe to Use in 2026?
Use With Caution
Score 63/100WM JqMath has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wm-jqmath plugin v1.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code appears to follow best practices by not utilizing dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, indicating a history of stable and secure development or a lack of prior discovery. The limited attack surface, consisting solely of two shortcodes, is also a positive sign. However, the complete absence of nonce checks and capability checks on these shortcodes represents a potential oversight. While no vulnerabilities are immediately apparent from the static analysis due to the lack of complex flows, an attacker could potentially exploit these entry points if they were to lead to any sensitive operations or unintended behavior that isn't properly secured.
Key Concerns
- Shortcodes lack nonce checks
- Shortcodes lack capability checks
WM JqMath Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
WM JqMath Release Timeline
WM JqMath Code Analysis
WM JqMath Attack Surface
Shortcodes 2
Maintenance & Trust
WM JqMath Maintenance & Trust
Maintenance Signals
Community Trust
WM JqMath Alternatives
JTL-Connector for WooCommerce
woo-jtl-connector
Extend your shop software, trough this connector, with an full ERP with many features for marketplaces etc.
WPML Shortcode Translator
wpml-short-code-translator
WPML.org plugin users now can use language detection shortcode anywhere, e.g. text blocks.
ViewMedica 9
viewmedica
ViewMedica 9 for WordPress Instantly embed your ViewMedica On-Demand in to your website
Remove Links and Scripts
remove-links-and-scripts
Remove unwanted links and scripts from wordpress header.
Clean up wp_head
clean-up-wp-head
Use Clean up wp_head to remove unused tags in wp_head.
WM JqMath Developer Profile
1 plugin · 20 total installs
How We Detect WM JqMath
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wm-jqmath/css/jqmath-0.4.3.css/wp-content/plugins/wm-jqmath/js/jqmath-etc-0.4.3.min.js/wp-content/plugins/wm-jqmath/js/jqmath-etc-0.4.3.min.jswm-jqmath/css/jqmath-0.4.3.css?ver=wm-jqmath/js/jqmath-etc-0.4.3.min.js?ver=HTML / DOM Fingerprints
style<span