GDEZAKAZI.RU Security & Risk Analysis

wordpress.org/plugins/gdezakazi-ru

ГДЕЗАКАЗЫ.РФ - отслеживание посылок Почта России v.1.0 Разработано ГДЕЗАКАЗЫ.РФ Модуль использует функционал сервиса ГДЕЗАКАЗЫ.

10 active installs v1.0 PHP 5.6+ WP 5.1+ Updated Sep 16, 2020
%d0%bf%d0%be%d1%87%d1%82%d0%b0-%d1%80%d0%be%d1%81%d1%81%d0%b8%d0%b8%d0%be%d1%82%d1%81%d0%bb%d0%b5%d0%b6%d0%b8%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5%d0%be%d1%82%d1%81%d0%bb%d0%b5%d0%b6%d0%b8%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d0%bf%d0%be%d1%81%d1%8b%d0%bb%d0%ba%d0%b8%d0%be%d1%82%d1%81%d0%bb%d0%b5%d0%b6%d0%b8%d0%b2%d0%b0%d0%bd%d0%b8%d0%b5-%d0%bf%d0%be%d1%81%d1%8b%d0%bb%d0%be%d0%ba%d1%82%d1%80%d0%b5%d0%ba%d0%b8%d0%bd%d0%b3
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GDEZAKAZI.RU Safe to Use in 2026?

Generally Safe

Score 85/100

GDEZAKAZI.RU has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "gdezakazi-ru" v1.0 plugin exhibits a concerning security posture due to a significant lack of input validation and authorization checks. The static analysis reveals two AJAX handlers, both of which are entirely unprotected. This represents a substantial attack surface, as any unauthenticated user can potentially trigger these functions. Furthermore, the plugin performs SQL queries without using prepared statements, increasing the risk of SQL injection vulnerabilities. While there are no known vulnerabilities in its history, this is likely due to the limited attack surface in other areas (e.g., no shortcodes, no REST API routes) rather than robust security practices.

The identified taint flow with an unsanitized path, combined with the unprotected AJAX handlers, suggests a high risk of arbitrary file access or manipulation if the AJAX endpoints interact with the file system or user-supplied paths. The lack of nonce and capability checks on the AJAX handlers exacerbates this risk, allowing any visitor to execute potentially sensitive code. The plugin also has external HTTP requests, which could be exploited if the targets of these requests are controllable or if the plugin doesn't properly validate the responses.

While the absence of critical code signals like dangerous functions is a positive aspect, it is heavily overshadowed by the critical vulnerabilities in access control and data handling. The 50% rate of proper output escaping is also a weakness, as it implies that half of the plugin's outputs are susceptible to cross-site scripting (XSS) attacks. The vulnerability history being clear of CVEs is a good sign but doesn't negate the inherent risks present in the current code. In conclusion, "gdezakazi-ru" v1.0 has significant security weaknesses that require immediate attention, primarily concerning its unprotected AJAX endpoints and raw SQL queries.

Key Concerns

  • AJAX handlers without auth checks
  • SQL queries without prepared statements
  • Flows with unsanitized paths (taint analysis)
  • Output escaping is not fully proper (50% good)
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

GDEZAKAZI.RU Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GDEZAKAZI.RU Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

50% escaped10 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-gdezakazy-order> (class-gdezakazy-order.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

GDEZAKAZI.RU Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_gdezakazy_addclass-gdezakazy-order.php:14
authwp_ajax_gdezakazy_archiveclass-gdezakazy-order.php:15
WordPress Hooks 10
actionadd_meta_boxesclass-gdezakazy-order.php:11
actionadmin_print_stylesclass-gdezakazy-order.php:12
actionadmin_print_scriptsclass-gdezakazy-order.php:13
actiongdezakazy_hourly_eventclass-gdezakazy-order.php:17
filterwp_mail_fromclass-gdezakazy-order.php:148
filterwp_mail_from_nameclass-gdezakazy-order.php:149
actionadmin_menuclass-gdezakazy-settings.php:19
actionadmin_initclass-gdezakazy-settings.php:20
actionadmin_print_stylesclass-gdezakazy-settings.php:21
actionadmin_print_scriptsclass-gdezakazy-settings.php:22

Scheduled Events 1

gdezakazy_hourly_event
Maintenance & Trust

GDEZAKAZI.RU Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedSep 16, 2020
PHP min version5.6
Downloads901

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

GDEZAKAZI.RU Developer Profile

kabetov

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GDEZAKAZI.RU

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gdezakazi-ru/css/order.css/wp-content/plugins/gdezakazi-ru/js/order.js
Script Paths
/wp-content/plugins/gdezakazi-ru/js/order.js
Version Parameters
gdezakazi_order_stylesgdezakazi_order_script

HTML / DOM Fingerprints

CSS Classes
gdezakazy_order_wrap
FAQ

Frequently Asked Questions about GDEZAKAZI.RU