ClickMis Accounting Security & Risk Analysis

wordpress.org/plugins/clickmis

اتصال و همگامسازی وب سایت فروش ووکامرس با حسابداری آنلاین کلیک

10 active installs v1.1.6 PHP 5.6+ WP 5.2+ Updated Jul 18, 2026
accounting-cloud-clickmisclickmis%da%a9%d9%84%db%8c%da%a9
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ClickMis Accounting Safe to Use in 2026?

Generally Safe

Score 100/100

ClickMis Accounting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "clickmis" v1.0.7 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. A significant strength is the absence of dangerous functions, file operations, external HTTP requests, and a complete lack of raw SQL queries, with all SQL queries using prepared statements. Furthermore, all identified output is properly escaped, and there are no recorded vulnerabilities or CVEs, suggesting a well-maintained and secure codebase. The plugin also demonstrates a commendable approach to its REST API routes, ensuring that all 11 routes have permission callbacks, leaving zero unprotected entry points in this area.

Despite these positive indicators, a notable area of concern is the complete absence of nonce checks and capability checks. While the REST API routes are protected by permission callbacks, the lack of nonce checks for AJAX handlers and general capability checks throughout the code could potentially introduce vulnerabilities if other entry points were to exist or if the existing permission callbacks were to be bypassed or become insufficient in the future. The absence of any taint analysis data also means that there's an unknown potential for complex vulnerabilities that static analysis might miss, though the overall code quality suggests this is less likely.

In conclusion, "clickmis" v1.0.7 is a secure plugin with excellent adherence to best practices regarding SQL and output escaping, and a clean vulnerability history. The primary weakness lies in the overlooked nonce and capability checks, which, while not demonstrably exploited in this version based on the data, represent a gap in defense-in-depth. The lack of taint analysis also leaves a small unknown. However, the overall security is high, and the plugin is a good choice for users.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ClickMis Accounting Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ClickMis Accounting Release Timeline

v1.5.1
v1.1.6Current
v1.1.5
v1.1.4
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0
Code Analysis
Analyzed Mar 16, 2026

ClickMis Accounting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

ClickMis Accounting Attack Surface

Entry Points11
Unprotected0

REST API Routes 11

GET/wp-json/ClickPlugin/v1/testClickPlugin.php:1373
GET/wp-json/ClickPlugin/v1/productsClickPlugin.php:1379
GET/wp-json/ClickPlugin/v1/full_productsClickPlugin.php:1385
GET/wp-json/ClickPlugin/v1/variationsClickPlugin.php:1391
POST/wp-json/ClickPlugin/v1/syncClickPlugin.php:1397
GET/wp-json/ClickPlugin/v1/categoriesClickPlugin.php:1403
GET/wp-json/ClickPlugin/v1/productsFullClickPlugin.php:1409
GET/wp-json/ClickPlugin/v1/ordersClickPlugin.php:1415
GET/wp-json/ClickPlugin/v1/ordersFullClickPlugin.php:1421
GET/wp-json/ClickPlugin/v1/customersClickPlugin.php:1427
GET/wp-json/ClickPlugin/v1/customersFullClickPlugin.php:1433
WordPress Hooks 2
filterwoocommerce_max_webhook_delivery_failuresClickPlugin.php:38
actionrest_api_initClickPlugin.php:1365
Maintenance & Trust

ClickMis Accounting Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJul 18, 2026
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ClickMis Accounting Developer Profile

clickmis

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ClickMis Accounting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clickmis/css/clickmis.css/wp-content/plugins/clickmis/js/clickmis.js
Generator Patterns
ClickPlugin v1.0.7
Version Parameters
clickmis/css/clickmis.css?ver=clickmis/js/clickmis.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ClickMis Accounting