Фискализация чеков е-ОФД Security & Risk Analysis

wordpress.org/plugins/eofdsupport

Плагин для WooCommerce, для фискализации чеков согласно 54 ФЗ, арендованной облачной онлайн кассы оператора фискальных данных е-ОФД.

10 active installs v1.0.8 PHP 5.3+ WP 4.8+ Updated Dec 30, 2025
54-%d1%84%d0%b7%d0%ba%d0%ba%d1%82%d0%be%d0%b1%d0%bb%d0%b0%d1%87%d0%bd%d0%b0%d1%8f-%d0%ba%d0%b0%d1%81%d1%81%d0%b0%d0%be%d0%bd%d0%bb%d0%b0%d0%b9%d0%bd-%d0%ba%d0%b0%d1%81%d1%81%d0%b0%d0%be%d0%bd%d0%bb%d0%b0%d0%b9%d0%bd-%d0%ba%d0%b0%d1%81%d1%81%d0%b0-%d0%b4%d0%bb%d1%8f-%d0%b8%d0%bd%d1%82%d0%b5%d1%80%d0%bd%d0%b5%d1%82-%d0%bc%d0%b0%d0%b3%d0%b0%d0%b7%d0%b8%d0%bd%d0%b0
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Фискализация чеков е-ОФД Safe to Use in 2026?

Generally Safe

Score 100/100

Фискализация чеков е-ОФД has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The eofdsupport v1.0.8 plugin exhibits a concerning security posture primarily due to its unprotected AJAX handler, which represents a significant attack vector. While the plugin demonstrates good practices in terms of output escaping and avoids dangerous functions or file operations, the absence of authentication and capability checks on an entry point is a critical oversight. The presence of two flows with unsanitized paths in the taint analysis, though not reaching a critical or high severity in this specific scan, hints at potential vulnerabilities if user-supplied data is not properly validated and sanitized before being used in SQL queries or other sensitive operations. The plugin's clean vulnerability history is positive, suggesting a lack of past exploitation or discovery. However, this should not overshadow the immediate risks posed by the identified code signals.

Key Concerns

  • Unprotected AJAX handler
  • Raw SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
  • Flows with unsanitized paths
Vulnerabilities
None known

Фискализация чеков е-ОФД Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Фискализация чеков е-ОФД Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
7
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

83% escaped41 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
eofdsupport_check_connection (eofdsupport.php:141)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Фискализация чеков е-ОФД Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_eofdsupporteofdsupport.php:139
WordPress Hooks 5
actionwpeofdsupport.php:30
actioneofdsupport_my_hourly_eventeofdsupport.php:45
actionadmin_menueofdsupport.php:117
actionadmin_initeofdsupport.php:129
actionwoocommerce_order_status_changedeofdsupport.php:196

Scheduled Events 2

eofdsupport_my_hourly_event
eofdsupport_my_hourly_event
Maintenance & Trust

Фискализация чеков е-ОФД Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 30, 2025
PHP min version5.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Фискализация чеков е-ОФД Developer Profile

е-ОФД

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Фискализация чеков е-ОФД

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eofdsupport/css/eofdsupport-styles.css/wp-content/plugins/eofdsupport/js/eofdsupport-scripts.js
Script Paths
/wp-content/plugins/eofdsupport/js/eofdsupport-scripts.js
Version Parameters
eofdsupport-scripts.js?ver=1.0.8

HTML / DOM Fingerprints

CSS Classes
err
JS Globals
eofdsupport_check_connectioneofdsupport_settings
REST Endpoints
/wp-json/eofdsupport/
FAQ

Frequently Asked Questions about Фискализация чеков е-ОФД