
Geliver Akıllı Kargo Pazaryeri Security & Risk Analysis
wordpress.org/plugins/geliver-akilli-kargo-pazaryeriGeliver, tüm kargo süreçlerinizi yöneten, indirimli fiyatlarla çalışan bulut tabanlı bir kargo pazaryeri sistemidir. Kargo firmaları ile anlaşma yapma …
Is Geliver Akıllı Kargo Pazaryeri Safe to Use in 2026?
Generally Safe
Score 100/100Geliver Akıllı Kargo Pazaryeri has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "geliver-akilli-kargo-pazaryeri" v2.2.0 exhibits a mixed security posture. While it demonstrates good practices by largely utilizing prepared statements for SQL queries and proper output escaping, significant concerns arise from its unprotected entry points. The analysis reveals one AJAX handler and one REST API route that lack proper authentication or permission checks, presenting a direct attack vector for unauthenticated users. The presence of one flow with unsanitized paths in the taint analysis, although not categorized as critical or high severity, warrants attention as it could potentially lead to unexpected behavior or vulnerabilities if exploited in conjunction with the unprotected entry points.
The plugin's vulnerability history is clean, with no recorded CVEs. This lack of past vulnerabilities is a positive sign, suggesting either a history of secure development or a lack of significant public scrutiny. However, it is crucial not to let this history overshadow the identified weaknesses in the current version. The absence of capability checks and nonce checks on AJAX handlers are also notable omissions that increase the risk associated with the unprotected AJAX endpoint.
In conclusion, while the plugin avoids common pitfalls like dangerous functions and outdated bundled libraries, the unprotected AJAX and REST API routes, combined with a potentially unsanitized path flow, create a notable security risk. The absence of explicit capability checks on these entry points is a significant concern. The excellent record of no past CVEs is a strength, but the identified vulnerabilities in the current static analysis necessitate attention and mitigation.
Key Concerns
- Unprotected AJAX handlers without auth checks
- Unprotected REST API routes without permission callbacks
- Flows with unsanitized paths detected
- No capability checks detected
- Missing nonce checks on AJAX
Geliver Akıllı Kargo Pazaryeri Security Vulnerabilities
Geliver Akıllı Kargo Pazaryeri Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Geliver Akıllı Kargo Pazaryeri Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 32
Maintenance & Trust
Geliver Akıllı Kargo Pazaryeri Maintenance & Trust
Maintenance Signals
Community Trust
Geliver Akıllı Kargo Pazaryeri Alternatives
Kargo Takip
kargo-takip-turkiye
WooCommerce siparişlerinize kargo takip bilgisi ekleyin ve müşterilerinize otomatik e-posta/SMS bildirimleri gönderin.
Cargo Tracking for WooCommerce
cargo-tracking-for-woocommerce
With the WooCommerce cargo tracking plugin, you can add as many cargo companies as you want, show cargo tracking links on the front and admin side, an …
Kargo Takip
kargo-takip
Müşterilerinizin kargolarını takip etmesine olanak sağlayan bir kargo takip eklentisidir. Kargo takip eklentisi aras kargo, mng kargo , sürat kargo ve …
shipmendo – Lite
wc-shipmendo-lite
shipmendo - Lite kullanarak siparişlerin kargo adımlarını müşterilerinizle paylaşın. Desteklenen kargo firmaları: - Aras Kargo, - MNG Kargo, - PTT Kar …
Eafatura Kargo & E-Arşiv ve E-Fatura Entegrasyonu
eafatura-e-arsiv-entegrasyon
Kısa açıklama: WordPress WooCommerce için Fatura ve Kargo eklentisi.
Geliver Akıllı Kargo Pazaryeri Developer Profile
1 plugin · 300 total installs
How We Detect Geliver Akıllı Kargo Pazaryeri
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/surat_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/yurtici_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/aras_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/sendeo_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/hepsijet_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/ptt_standart.pngHTML / DOM Fingerprints
geliver_tracking_companygeliver_tracking_codegeliver_tracking_url