České služby pro WordPress Security & Risk Analysis

wordpress.org/plugins/ceske-sluzby

Implementace různých českých služeb do WordPressu (zejména pro WooCommerce)

1K active installs v0.5 PHP + WP 4.0+ Updated Sep 16, 2016
heureka-czsklik-czsrovname-czulozenka-czwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is České služby pro WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

České služby pro WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "ceske-sluzby" v0.5 plugin exhibits a generally good security posture based on the provided static analysis. The plugin has a small attack surface, with no unprotected entry points identified. Notably, all SQL queries utilize prepared statements, indicating a strong defense against SQL injection. The absence of known CVEs and a clean vulnerability history further contribute to its positive security assessment. However, a significant concern arises from the low percentage of properly escaped output (29%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or internal data might not be adequately sanitized before being displayed to users. While the plugin avoids dangerous functions and has limited external HTTP requests, the output escaping is a critical area that requires immediate attention. The plugin's strengths lie in its secure database interactions and limited attack vectors, but the lack of robust output sanitization presents a substantial weakness.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

České služby pro WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

České služby pro WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
39
16 escaped
Nonce Checks
1
Capability Checks
1
File Operations
12
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

29% escaped55 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-ceske-sluzby-sledovani-zasilek> (includes\class-ceske-sluzby-sledovani-zasilek.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

České služby pro WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[heureka-recenze-obchodu] ceske-sluzby.php:215
WordPress Hooks 61
actionwoocommerce_shipping_initceske-sluzby.php:183
filterwoocommerce_shipping_methodsceske-sluzby.php:184
actionwoocommerce_shipping_initceske-sluzby.php:186
filterwoocommerce_shipping_methodsceske-sluzby.php:187
actionwoocommerce_checkout_order_processedceske-sluzby.php:189
actionwoocommerce_thankyouceske-sluzby.php:190
actionwoocommerce_thankyouceske-sluzby.php:191
actionwoocommerce_thankyouceske-sluzby.php:192
filterwc_order_is_editableceske-sluzby.php:193
filterwoocommerce_package_ratesceske-sluzby.php:194
actionwoocommerce_review_order_after_shippingceske-sluzby.php:196
actionwoocommerce_add_shipping_order_itemceske-sluzby.php:197
actionwoocommerce_checkout_processceske-sluzby.php:198
actionwoocommerce_admin_order_data_after_billing_addressceske-sluzby.php:199
actionwoocommerce_email_after_order_tableceske-sluzby.php:200
actionwoocommerce_order_details_after_order_tableceske-sluzby.php:201
actionwoocommerce_review_order_after_shippingceske-sluzby.php:203
actionwoocommerce_add_shipping_order_itemceske-sluzby.php:204
actionwoocommerce_checkout_processceske-sluzby.php:205
actionwoocommerce_admin_order_data_after_billing_addressceske-sluzby.php:206
actionwoocommerce_email_after_order_tableceske-sluzby.php:207
actionwoocommerce_order_details_after_order_tableceske-sluzby.php:208
filterwoocommerce_pay4pay_cod_amountceske-sluzby.php:210
filterwoocommerce_pay4pay_cod_amountceske-sluzby.php:211
filterwoocommerce_email_classesceske-sluzby.php:220
filterwoocommerce_email_actionsceske-sluzby.php:221
filterwoocommerce_get_availability_textceske-sluzby.php:230
actionwoocommerce_before_add_to_cart_formceske-sluzby.php:233
actionwoocommerce_after_shop_loop_itemceske-sluzby.php:236
actionadmin_enqueue_scriptsceske-sluzby.php:242
actionproduct_cat_add_form_fieldsceske-sluzby.php:246
actionproduct_cat_edit_form_fieldsceske-sluzby.php:247
actioncreated_termceske-sluzby.php:248
actionedit_termceske-sluzby.php:249
filtermanage_edit-product_cat_columnsceske-sluzby.php:250
filtermanage_product_cat_custom_columnceske-sluzby.php:251
actionwp_footerceske-sluzby.php:253
actionplugins_loadedceske-sluzby.php:256
actioninitceske-sluzby.php:503
actionceske_sluzby_heureka_aktualizace_xmlceske-sluzby.php:563
actionceske_sluzby_heureka_aktualizace_xml_batchceske-sluzby.php:564
actionceske_sluzby_zbozi_aktualizace_xmlceske-sluzby.php:570
actionceske_sluzby_zbozi_aktualizace_xml_batchceske-sluzby.php:571
actionceske_sluzby_pricemania_aktualizace_xmlceske-sluzby.php:577
actionceske_sluzby_pricemania_aktualizace_xml_batchceske-sluzby.php:578
filterwoocommerce_settings_tabs_arrayincludes\class-ceske-sluzby-admin.php:6
actionwoocommerce_settings_tabs_ceske-sluzbyincludes\class-ceske-sluzby-admin.php:7
actionwoocommerce_update_options_ceske-sluzbyincludes\class-ceske-sluzby-admin.php:8
actionwoocommerce_sections_ceske-sluzbyincludes\class-ceske-sluzby-admin.php:9
filterwoocommerce_admin_settings_sanitize_optionincludes\class-ceske-sluzby-admin.php:10
filterwoocommerce_product_data_tabsincludes\class-ceske-sluzby-product-tab.php:6
actionwoocommerce_product_data_panelsincludes\class-ceske-sluzby-product-tab.php:7
actionwoocommerce_process_product_metaincludes\class-ceske-sluzby-product-tab.php:8
actionwoocommerce_product_options_stock_statusincludes\class-ceske-sluzby-product-tab.php:9
actionwoocommerce_ceske_sluzby_sledovani_zasilek_email_akce_notificationincludes\class-ceske-sluzby-sledovani-zasilek-email.php:20
filterwoocommerce_locate_core_templateincludes\class-ceske-sluzby-sledovani-zasilek-email.php:21
actionload-post.phpincludes\class-ceske-sluzby-sledovani-zasilek.php:9
actionadd_meta_boxesincludes\class-ceske-sluzby-sledovani-zasilek.php:77
actionwoocommerce_process_shop_order_metaincludes\class-ceske-sluzby-sledovani-zasilek.php:78
filterwoocommerce_resend_order_emails_availableincludes\class-ceske-sluzby-sledovani-zasilek.php:81
filterwoocommerce_hidden_order_itemmetaincludes\class-ceske-sluzby-sledovani-zasilek.php:83

Scheduled Events 9

ceske_sluzby_heureka_aktualizace_xml
ceske_sluzby_zbozi_aktualizace_xml
ceske_sluzby_pricemania_aktualizace_xml
ceske_sluzby_heureka_aktualizace_xml_batch
ceske_sluzby_heureka_aktualizace_xml_batch
ceske_sluzby_zbozi_aktualizace_xml_batch
ceske_sluzby_zbozi_aktualizace_xml_batch
ceske_sluzby_pricemania_aktualizace_xml_batch
ceske_sluzby_pricemania_aktualizace_xml_batch
Maintenance & Trust

České služby pro WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 16, 2016
PHP min version
Downloads70K

Community Trust

Rating100/100
Number of ratings20
Active installs1K
Developer Profile

České služby pro WordPress Developer Profile

pavelevap

4 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect České služby pro WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ceske-sluzby/includes/class-ceske-sluzby-admin.php/wp-content/plugins/ceske-sluzby/includes/class-ceske-sluzby-product-tab.php/wp-content/plugins/ceske-sluzby/includes/class-ceske-sluzby-sledovani-zasilek-email.php/wp-content/plugins/ceske-sluzby/includes/class-ceske-sluzby-sledovani-zasilek.php/wp-content/plugins/ceske-sluzby/includes/ceske-sluzby-functions.php
Script Paths
http://www.srovname.cz/js/track-trans.jshttp://c.imedia.cz/checkConversion
Version Parameters
ver=0.5

HTML / DOM Fingerprints

HTML Comments
<!-- Měřicí kód Sklik.cz -->
Data Attributes
name="wc_ceske_sluzby_heureka_overeno-api"name="wc_ceske_sluzby_heureka_konverze-api"name="wc_ceske_sluzby_heureka_certifikat_spokojenosti-aktivace"name="wc_ceske_sluzby_heureka_certifikat_spokojenosti_umisteni"name="wc_ceske_sluzby_heureka_certifikat_spokojenosti_odsazeni"name="wc_ceske_sluzby_sklik_konverze-objednavky"+2 more
JS Globals
_hrq_hwq_srt
FAQ

Frequently Asked Questions about České služby pro WordPress