
WPrequal Security & Risk Analysis
wordpress.org/plugins/wprequalEasy-to-use lead generation, lead capture, lead manager, and form builders. No advanced setup required; works well and looks great out-of-the-box.
Is WPrequal Safe to Use in 2026?
Generally Safe
Score 99/100WPrequal has a strong security track record. Known vulnerabilities have been patched promptly.
The "wprequal" plugin v8.4.1 exhibits a strong security posture based on the static analysis provided. The complete absence of dangerous functions, 100% utilization of prepared statements for SQL queries, and proper output escaping across all detected outputs are commendable practices. Furthermore, the presence of nonce and capability checks on all identified entry points, including AJAX handlers and shortcodes, indicates a proactive approach to preventing common web vulnerabilities.
Despite these strengths, there are minor concerns to note. The analysis reveals two flows with unsanitized paths, although they are not classified as critical or high severity. This suggests a potential, albeit low-risk, for path traversal or similar vulnerabilities. The plugin's history of one disclosed CVE, which is now patched, is not ideal but not a significant red flag given its current patched status. The presence of file operations and external HTTP requests, while not inherently insecure, are areas that warrant careful monitoring for potential future vulnerabilities.
In conclusion, "wprequal" v8.4.1 appears to be a relatively secure plugin due to its robust implementation of security best practices. The lack of critical or high-severity findings in static analysis and its currently patched vulnerability history are positive indicators. However, the minor taint analysis findings related to unsanitized paths should be addressed in future updates to further harden the plugin's security.
Key Concerns
- Flows with unsanitized paths detected
WPrequal Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mortgage Lead Capture System <= 8.2.11 - Cross-Site Request Forgery to Settings Reset
WPrequal Code Analysis
Output Escaping
Data Flow Analysis
WPrequal Attack Surface
AJAX Handlers 1
Shortcodes 7
WordPress Hooks 68
Maintenance & Trust
WPrequal Maintenance & Trust
Maintenance Signals
Community Trust
WPrequal Alternatives
Mortgage Calculator
mortgage-calculator
It provides an easy to use mortgage calculator widget.
Mortgage Calculators WP
mortgage-calculators-wp
Mortgage Calculators WP provides users with a simple, elegant and responsive solution for users to calculate mortgage values.
Advanced Real Estate Mortgage Calculator
advanced-real-estate-mortgage-calculator
Advanced Real Estate Mortgage Calculator is an easy-to-use financial calculator and a great tool for real estate websites.
Ultimate Loan & Mortgage Calculator
ultimate-loan-mortgage-calculator
For financial advisors and real estate professionals: the most effective loan & mortgage calculator plugin for WordPress!
Mortgage Calculator
mobile-friendly-mortgage-calculator
Mobile friendly mortgage calculator widget with extra payments and fields builder.
WPrequal Developer Profile
2 plugins · 180 total installs
How We Detect WPrequal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wprequal/assets/js/wprequal-app.min.js/wp-content/plugins/wprequal/assets/css/wprequal-app.min.css/wp-content/plugins/wprequal/assets/js/wprequal-calc.js/wp-content/plugins/wprequal/assets/js/wprequal.js/wp-content/plugins/wprequal/assets/js/wprequal-app.min.js/wp-content/plugins/wprequal/assets/js/wprequal-calc.js/wp-content/plugins/wprequal/assets/js/wprequal.jswprequal_jswprequal_calc_popupAmortizeHTML / DOM Fingerprints
wprequal-calccalc-hidecalc-button-shortcode<!-- Start Calc Popup Section --><!-- End Calc Popup Section --><!-- Start Calc Shortcode Section --><!-- End Calc Shortcode Section -->+2 moredata-loanTermTypedata-popupCalcdata-AmortizewprequalCalcwprequal_calc_popupAmortize/wp-json/wprequal/v3/nonce/wp-json/wprequal/v3/entry[wprequal_calc][wprequal_calc_button][wprequal_amortize]