WP Calorie Calculator Security & Risk Analysis

wordpress.org/plugins/wp-calorie-calculator

For all experts in fitness, health & calories-dependent nutrition or sports: meet the most effective marketing feature for your WordPress website!

1K active installs v4.4.0 PHP 5.6+ WP 4.7+ Updated Feb 21, 2026
calorie-calculatordietfitnesshealthnutrition
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Calorie Calculator Safe to Use in 2026?

Generally Safe

Score 100/100

WP Calorie Calculator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The wp-calorie-calculator plugin v4.4.0 demonstrates several positive security practices, including the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of any known vulnerabilities in its history is also a strong indicator of good security maintenance. However, the plugin presents a notable risk due to its attack surface. A significant portion of its entry points, specifically four out of five, lack authentication checks. This means unauthorized users could potentially interact with these components, leading to unintended consequences or exposing them to further exploitation if other vulnerabilities exist.

The static analysis reveals two taint flows with unsanitized paths. While these are not classified as critical or high severity, they represent potential security weaknesses where user-supplied data could be processed without adequate validation or sanitization. This, combined with the unprotected AJAX handlers, creates a scenario where an attacker might be able to inject malicious code or manipulate the plugin's functionality through these unauthenticated entry points. The presence of only one nonce check and one capability check on the entry points further exacerbates this risk, as these fundamental WordPress security mechanisms are not comprehensively applied.

Key Concerns

  • 4 unprotected AJAX handlers
  • 2 unsanitized taint flows
  • 1 unprotected shortcode
  • Limited nonce and capability checks
Vulnerabilities
None known

WP Calorie Calculator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Calorie Calculator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
140 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

93% escaped150 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
change_color_schema_callback (admin\class-wp-calorie-calculator-admin.php:249)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

WP Calorie Calculator Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_change_color_schemaincludes\class-wp-calorie-calculator.php:164
noprivwp_ajax_change_color_schemaincludes\class-wp-calorie-calculator.php:165
authwp_ajax_wpcc_send_resultincludes\class-wp-calorie-calculator.php:181
noprivwp_ajax_wpcc_send_resultincludes\class-wp-calorie-calculator.php:182

Shortcodes 1

[cal_calc] includes\class-wp-calorie-calculator.php:183
WordPress Hooks 10
actionplugins_loadedincludes\class-wp-calorie-calculator.php:139
actionadmin_noticesincludes\class-wp-calorie-calculator.php:155
actionadmin_noticesincludes\class-wp-calorie-calculator.php:156
actionadmin_enqueue_scriptsincludes\class-wp-calorie-calculator.php:157
actionadmin_enqueue_scriptsincludes\class-wp-calorie-calculator.php:158
actionadmin_menuincludes\class-wp-calorie-calculator.php:159
actionadmin_initincludes\class-wp-calorie-calculator.php:160
actionadmin_menuincludes\class-wp-calorie-calculator.php:163
actionwp_enqueue_scriptsincludes\class-wp-calorie-calculator.php:179
actionwp_enqueue_scriptsincludes\class-wp-calorie-calculator.php:180
Maintenance & Trust

WP Calorie Calculator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 21, 2026
PHP min version5.6
Downloads40K

Community Trust

Rating92/100
Number of ratings11
Active installs1K
Developer Profile

WP Calorie Calculator Developer Profile

THE BELOV

7 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Calorie Calculator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Calorie Calculator