Hedef Sanal POS Security & Risk Analysis

wordpress.org/plugins/hedef-sanal-pos

Hedef Sanal POS, WooCommerce mağazaları için birden fazla banka sanal POS entegrasyonunu tek panelden yönetmenizi sağlar.

0 active installs v0.1.1 PHP 7.4+ WP 6.0+ Updated Mar 14, 2026
bankasanal-postaksitturkiyewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hedef Sanal POS Safe to Use in 2026?

Generally Safe

Score 100/100

Hedef Sanal POS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The 'hedef-sanal-pos' plugin v0.1.1 demonstrates a generally strong security posture based on the provided static analysis. The plugin exhibits excellent practices regarding output escaping, with 99% of outputs properly handled, and a high percentage of SQL queries utilizing prepared statements (93%). The absence of dangerous functions, file operations, and critical/high severity taint flows further reinforces this positive outlook. The vulnerability history being clear of any recorded CVEs suggests a lack of previously discovered exploitable flaws.

However, there are a few areas that warrant attention. While the attack surface is small and currently has no unprotected entry points, relying solely on capability checks (4) and nonce checks (6) for the single shortcode could be a potential area for future concern if the plugin evolves. The presence of 8 external HTTP requests, while not inherently insecure, represents an indirect attack vector if those external services are compromised or if the plugin handles their responses without adequate sanitization, though current taint analysis shows no unsanitized paths.

In conclusion, 'hedef-sanal-pos' v0.1.1 appears to be a well-coded plugin from a security perspective, adhering to many best practices. The strengths lie in its robust output escaping and SQL handling, and its clean vulnerability history. The primary areas to monitor would be the continued security of its external HTTP requests and the diligent maintenance of authentication and authorization checks as the plugin develops.

Vulnerabilities
None known

Hedef Sanal POS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hedef Sanal POS Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
13 prepared
Unescaped Output
7
548 escaped
Nonce Checks
6
Capability Checks
4
File Operations
0
External Requests
8
Bundled Libraries
0

SQL Query Safety

93% prepared14 total queries

Output Escaping

99% escaped555 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<SavedCardsEndpoint> (src\Account\SavedCardsEndpoint.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hedef Sanal POS Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hedefsp_installment_table] src\Frontend\InstallmentDisplay.php:26
WordPress Hooks 50
filterwp_get_attachment_metadatahedef-sanal-pos.php:25
actionbefore_woocommerce_inithedef-sanal-pos.php:50
actionplugins_loadedhedef-sanal-pos.php:90
actioninitsrc\Account\SavedCardsEndpoint.php:26
actioninitsrc\Account\SavedCardsEndpoint.php:27
filterquery_varssrc\Account\SavedCardsEndpoint.php:28
filterwoocommerce_get_query_varssrc\Account\SavedCardsEndpoint.php:29
filterwoocommerce_account_menu_itemssrc\Account\SavedCardsEndpoint.php:32
actiontemplate_redirectsrc\Account\SavedCardsEndpoint.php:41
actionadmin_menusrc\Admin\AdminMenu.php:19
actionadmin_menusrc\Admin\AdminMenu.php:21
actionadmin_enqueue_scriptssrc\Admin\Assets.php:12
actionadmin_initsrc\Admin\BankSettingsPage.php:79
actionproduct_cat_add_form_fieldssrc\Admin\CategoryInstallmentMeta.php:13
actionproduct_cat_edit_form_fieldssrc\Admin\CategoryInstallmentMeta.php:16
actioncreated_product_catsrc\Admin\CategoryInstallmentMeta.php:19
actionedited_product_catsrc\Admin\CategoryInstallmentMeta.php:20
actionproduct_cat_add_form_fieldssrc\Admin\CategoryMeta.php:12
actionproduct_cat_edit_form_fieldssrc\Admin\CategoryMeta.php:13
actioncreated_product_catsrc\Admin\CategoryMeta.php:15
actionedited_product_catsrc\Admin\CategoryMeta.php:16
actionadmin_initsrc\Admin\GateSettingsPage.php:34
actionadmin_initsrc\Admin\GeneralSettingsPage.php:21
actionadd_meta_boxessrc\Admin\OrderMetaBox.php:26
filterwoocommerce_order_actionssrc\Admin\OrderMetaBox.php:29
actionwoocommerce_order_action_hedefsp_voidsrc\Admin\OrderMetaBox.php:32
actionwoocommerce_order_action_hedefsp_refund_fullsrc\Admin\OrderMetaBox.php:33
actionwoocommerce_product_options_general_product_datasrc\Admin\ProductInstallmentMeta.php:15
actionwoocommerce_admin_process_product_objectsrc\Admin\ProductInstallmentMeta.php:18
actionadd_meta_boxessrc\Admin\ProductMeta.php:12
actionsave_post_productsrc\Admin\ProductMeta.php:13
actionadmin_noticessrc\Bootstrap.php:58
actionelementor/loadedsrc\Bootstrap.php:84
actionelementor/widgets/registersrc\Elementor\Plugin.php:25
actionelementor/elements/categories_registeredsrc\Elementor\Plugin.php:26
actionwp_enqueue_scriptssrc\Frontend\Assets.php:21
actionwoocommerce_api_hedefsp_akbank_oksrc\Gateways\AkbankJson3DCallbackHandler.php:22
actionwoocommerce_api_hedefsp_akbank_failsrc\Gateways\AkbankJson3DCallbackHandler.php:23
actionwoocommerce_api_hedefsp_garanti_oksrc\Gateways\Garanti3DCallbackHandler.php:24
actionwoocommerce_api_hedefsp_garanti_failsrc\Gateways\Garanti3DCallbackHandler.php:25
filterwoocommerce_payment_gatewayssrc\Gateways\Gateway_Loader.php:12
actionwp_enqueue_scriptssrc\Gateways\Hedefsp_WC_Gateway_HedefSanalPos.php:58
actionwoocommerce_api_hedefsp_paytr_notifysrc\Gateways\PaytrCallbackHandler.php:21
actionwoocommerce_api_hedefsp_paytr_oksrc\Gateways\PaytrCallbackHandler.php:22
actionwoocommerce_api_hedefsp_paytr_failsrc\Gateways\PaytrCallbackHandler.php:23
actionwoocommerce_api_hedefsp_qnb_oksrc\Gateways\Qnb3DCallbackHandler.php:20
actionwoocommerce_api_hedefsp_qnb_failsrc\Gateways\Qnb3DCallbackHandler.php:21
actionwoocommerce_api_hedefsp_ziraat_oksrc\Gateways\Ziraat3DCallbackHandler.php:18
actionwoocommerce_api_hedefsp_ziraat_failsrc\Gateways\Ziraat3DCallbackHandler.php:19
actionwoocommerce_api_hedefsp_ziraat_callbacksrc\Gateways\Ziraat3DCallbackHandler.php:20
Maintenance & Trust

Hedef Sanal POS Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads135

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hedef Sanal POS Developer Profile

hedefhosting1

2 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hedef Sanal POS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hedef-sanal-pos/assets/css/admin.css/wp-content/plugins/hedef-sanal-pos/assets/js/admin.js/wp-content/plugins/hedef-sanal-pos/assets/css/frontend.css/wp-content/plugins/hedef-sanal-pos/assets/js/hedefsp-installments.js
Version Parameters
hedef-sanal-pos/assets/css/admin.css?ver=hedef-sanal-pos/assets/js/admin.js?ver=hedef-sanal-pos/assets/css/frontend.css?ver=hedef-sanal-pos/assets/js/hedefsp-installments.js?ver=

HTML / DOM Fingerprints

REST Endpoints
wc-api/hedefsp_akbank_okwc-api/hedefsp_akbank_fail
FAQ

Frequently Asked Questions about Hedef Sanal POS