Fakturo Stock in List Security & Risk Analysis

wordpress.org/plugins/etruel-stock-in-list-for-eshop

Fakturo Addon that adds a column specifying the stock of each product among other features like print or export Products list.

10 active installs v1.0.0 PHP 7.0+ WP 4.9+ Updated Jul 26, 2024
accountantaddonfakturoinvoicepdf
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fakturo Stock in List Safe to Use in 2026?

Generally Safe

Score 92/100

Fakturo Stock in List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "etruel-stock-in-list-for-eshop" v1.0.0 demonstrates a generally good security posture with no known historical vulnerabilities or CVEs. The static analysis reveals a commendably small attack surface with zero unprotected entry points. Importantly, all detected SQL queries utilize prepared statements, mitigating common SQL injection risks. The presence of a nonce check and a capability check further bolsters its security by enforcing necessary validations.

However, the code analysis does present some areas of concern. Two out of four analyzed taint flows show unsanitized paths, indicating a potential for security vulnerabilities if these flows are exploitable. Furthermore, a significant portion of output operations (86%) are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization. The single file operation also warrants careful review to ensure it is performed securely.

Given the absence of historical vulnerabilities and the proactive security measures identified, the plugin appears to be developed with security in mind. Nevertheless, the identified taint flows and unescaped output represent genuine risks that need to be addressed to ensure robust security. The lack of known vulnerabilities suggests that these issues may not be easily exploitable or have not been discovered, but they still represent potential weaknesses.

Key Concerns

  • Unsanitized taint flows
  • High percentage of unescaped output
  • Single file operation requires review
Vulnerabilities
None known

Fakturo Stock in List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fakturo Stock in List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
12
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

14% escaped14 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
print_buttons_reports (includes\proccess.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fakturo Stock in List Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedfakturo_stock_in_list.php:177
actionadmin_noticesincludes\class.extension-activation.php:73
filterplugin_row_metaincludes\plugin_functions.php:10
filtermanage_fktr_product_posts_columnsincludes\proccess.php:8
filtermanage_fktr_product_posts_custom_columnincludes\proccess.php:10
filtermanage_edit-fktr_product_sortable_columnsincludes\proccess.php:12
actionrestrict_manage_postsincludes\proccess.php:14
filterget_objects_reports_fktr_productincludes\proccess.php:16
actionadmin_post_products_print_pdfincludes\proccess.php:19
actionadmin_post_products_download_csvincludes\proccess.php:21
actionadmin_menuincludes\settings.php:15
filterftkr_tabs_sectionsincludes\settings.php:16
actionadmin_post_save_fkrt_stock_in_listincludes\settings.php:17
Maintenance & Trust

Fakturo Stock in List Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 26, 2024
PHP min version7.0
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Fakturo Stock in List Developer Profile

etruel

11 plugins · 13K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
116 days
View full developer profile
Detection Fingerprints

How We Detect Fakturo Stock in List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/etruel-stock-in-list-for-eshop/assets/js/fktr_stock_in_list.js
Script Paths
/wp-content/plugins/etruel-stock-in-list-for-eshop/assets/js/fktr_stock_in_list.js
Version Parameters
etruel-stock-in-list-for-eshop/assets/js/fktr_stock_in_list.js?ver=1.0.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Fakturo Stock in List