Geliver Akıllı Kargo Pazaryeri Security & Risk Analysis

wordpress.org/plugins/geliver-akilli-kargo-pazaryeri

Geliver, tüm kargo süreçlerinizi yöneten, indirimli fiyatlarla çalışan bulut tabanlı bir kargo pazaryeri sistemidir. Kargo firmaları ile anlaşma yapma …

300 active installs v2.2.0 PHP 7.2+ WP 6.0+ Updated Jun 4, 2025
geliverkargokargo-entegrasyonukargo-takipshipment-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Geliver Akıllı Kargo Pazaryeri Safe to Use in 2026?

Generally Safe

Score 100/100

Geliver Akıllı Kargo Pazaryeri has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "geliver-akilli-kargo-pazaryeri" v2.2.0 exhibits a mixed security posture. While it demonstrates good practices by largely utilizing prepared statements for SQL queries and proper output escaping, significant concerns arise from its unprotected entry points. The analysis reveals one AJAX handler and one REST API route that lack proper authentication or permission checks, presenting a direct attack vector for unauthenticated users. The presence of one flow with unsanitized paths in the taint analysis, although not categorized as critical or high severity, warrants attention as it could potentially lead to unexpected behavior or vulnerabilities if exploited in conjunction with the unprotected entry points.

The plugin's vulnerability history is clean, with no recorded CVEs. This lack of past vulnerabilities is a positive sign, suggesting either a history of secure development or a lack of significant public scrutiny. However, it is crucial not to let this history overshadow the identified weaknesses in the current version. The absence of capability checks and nonce checks on AJAX handlers are also notable omissions that increase the risk associated with the unprotected AJAX endpoint.

In conclusion, while the plugin avoids common pitfalls like dangerous functions and outdated bundled libraries, the unprotected AJAX and REST API routes, combined with a potentially unsanitized path flow, create a notable security risk. The absence of explicit capability checks on these entry points is a significant concern. The excellent record of no past CVEs is a strength, but the identified vulnerabilities in the current static analysis necessitate attention and mitigation.

Key Concerns

  • Unprotected AJAX handlers without auth checks
  • Unprotected REST API routes without permission callbacks
  • Flows with unsanitized paths detected
  • No capability checks detected
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Geliver Akıllı Kargo Pazaryeri Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Geliver Akıllı Kargo Pazaryeri Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
16 prepared
Unescaped Output
19
164 escaped
Nonce Checks
5
Capability Checks
0
File Operations
5
External Requests
3
Bundled Libraries
0

SQL Query Safety

94% prepared17 total queries

Output Escaping

90% escaped183 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

7 flows1 with unsanitized paths
<geliver-plugin> (geliver-plugin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Geliver Akıllı Kargo Pazaryeri Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 1

authwp_ajax_geliver_webhook_listenergeliver-plugin.php:43

REST API Routes 1

GET/wp-json/geliver/v1/webhookincludes\geliver-api-integration.php:14
WordPress Hooks 32
filterwoocommerce_shipping_methodsgeliver-plugin.php:18
actionwoocommerce_initgeliver-plugin.php:22
actionwoocommerce_shipping_initgeliver-plugin.php:23
filterwoocommerce_shipping_methodsgeliver-plugin.php:29
actionadmin_menugeliver-plugin.php:42
actioninitgeliver-plugin.php:60
filterwc_order_statusesgeliver-plugin.php:66
actionwoocommerce_admin_order_data_after_order_detailsgeliver-plugin.php:98
actionwoocommerce_process_shop_order_metageliver-plugin.php:161
actionwoocommerce_order_details_after_order_tablegeliver-plugin.php:197
actionwp_enqueue_scriptsgeliver-plugin.php:202
filterwoocommerce_my_account_my_orders_actionsgeliver-plugin.php:216
actionwoocommerce_order_status_kargo-verildigeliver-plugin.php:271
actionadmin_menuincludes\geliver-admin-functions.php:6
actionadmin_initincludes\geliver-admin-functions.php:48
actionadmin_enqueue_scriptsincludes\geliver-admin-functions.php:66
actionadmin_noticesincludes\geliver-admin-functions.php:82
actionupdate_option_geliver_akilli_kargo_plugin_modeincludes\geliver-api-integration.php:12
actionrest_api_initincludes\geliver-api-integration.php:13
actionwoocommerce_thankyouincludes\geliver-api-integration.php:23
actionwoocommerce_thankyouincludes\geliver-api-integration.php:28
actionwoocommerce_order_status_changedincludes\geliver-api-integration.php:565
actionwoocommerce_cart_updatedincludes\geliver-shipment-options.php:13
filtermanage_woocommerce_page_wc-orders_columnsincludes\pages\geliver-order-columns.php:16
filtermanage_edit-shop_order_columnsincludes\pages\geliver-order-columns.php:17
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\pages\geliver-order-columns.php:44
actionmanage_shop_order_posts_custom_columnincludes\pages\geliver-order-columns.php:45
actionadmin_post_send_order_to_apiincludes\pages\geliver-order-columns.php:111
actionadmin_post_nopriv_send_order_to_apiincludes\pages\geliver-order-columns.php:112
actionadmin_enqueue_scriptsincludes\pages\geliver-order-columns.php:124
actionadmin_enqueue_scriptsincludes\pages\geliver-order-columns.php:125
actionadmin_noticesincludes\pages\geliver-setting-page.php:47
Maintenance & Trust

Geliver Akıllı Kargo Pazaryeri Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 4, 2025
PHP min version7.2
Downloads3K

Community Trust

Rating80/100
Number of ratings3
Active installs300
Developer Profile

Geliver Akıllı Kargo Pazaryeri Developer Profile

Geliver A.Ş.

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Geliver Akıllı Kargo Pazaryeri

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/surat_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/yurtici_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/aras_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/sendeo_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/hepsijet_standart.png/wp-content/plugins/geliver-akilli-kargo-pazaryeri/assets/ptt_standart.png

HTML / DOM Fingerprints

Data Attributes
geliver_tracking_companygeliver_tracking_codegeliver_tracking_url
FAQ

Frequently Asked Questions about Geliver Akıllı Kargo Pazaryeri