
Информер ветки git Security & Risk Analysis
wordpress.org/plugins/iksweb-gitПлагин добавляет кнопку-информер в админ. панель в публичной части, с помощью которой можно узнать текущую ветку git, а так же изменить ее.
Is Информер ветки git Safe to Use in 2026?
Generally Safe
Score 85/100Информер ветки git has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "iksweb-git" plugin v2.3 exhibits a mixed security posture. On one hand, its attack surface appears to be extremely small, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests or file operations, which are positive signs. The lack of any recorded vulnerabilities in its history is also encouraging.
However, the static analysis reveals significant concerns. The presence of seven "exec" function calls is a critical red flag, as these functions can be highly dangerous if they are used in conjunction with user-supplied input without proper sanitization. The taint analysis indicates three flows with "unsanitized paths," suggesting that data might be flowing into these potentially dangerous functions without adequate cleaning. Compounding this, 100% of output is not properly escaped, which opens the door to cross-site scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks, while the attack surface is zero, means that any potential future expansion of the plugin's entry points could be immediately vulnerable without these essential security mechanisms.
In conclusion, while the plugin's current attack surface is negligible and it has a clean vulnerability history, the static analysis points to a high potential for severe vulnerabilities if the "exec" functions are indeed exposed to user input and the unescaped output allows for XSS. The lack of basic security checks like nonces and capability checks, even with a zero attack surface, represents a significant weakness in its security design that could be exploited if the plugin evolves.
Key Concerns
- Dangerous functions (exec) found
- Flows with unsanitized paths found
- Output not properly escaped
- No nonce checks
- No capability checks
Информер ветки git Security Vulnerabilities
Информер ветки git Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Информер ветки git Attack Surface
WordPress Hooks 5
Maintenance & Trust
Информер ветки git Maintenance & Trust
Maintenance Signals
Community Trust
Информер ветки git Alternatives
GitHub Repository Shortcode
f13-github-repo-shortcode
Add a snapshot of your GitHub repository to any page or post on your WordPress blog.
Show Git Branch
show-git-branch
Shows the git branch you are currently on in the Toolbar. Checks theme then root.
CC-Update
cc-update
This plugin allows you to automatically send changes to your GIT repository, immediately after any update is made on your site.
Projects Manager for GitHub
projects-manager-for-github
Fetch public GitHub repositories via API and display them as native WordPress projects with your theme's header and footer.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Информер ветки git Developer Profile
2 plugins · 310 total installs
How We Detect Информер ветки git
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iksweb-git/assets/css/iksweb.css/wp-content/plugins/iksweb-git/assets/js/bootstrap.tooltip.min.js/wp-content/plugins/iksweb-git/assets/js/iksweb.js/wp-content/plugins/iksweb-git/assets/css/style.css/wp-content/plugins/iksweb-git/assets/js/script.js/wp-content/plugins/iksweb-git/assets/js/bootstrap.tooltip.min.js/wp-content/plugins/iksweb-git/assets/js/iksweb.js/wp-content/plugins/iksweb-git/assets/js/script.jsiksweb-git/assets/css/iksweb.css?ver=iksweb-git/assets/js/bootstrap.tooltip.min.js?ver=iksweb-git/assets/js/iksweb.js?ver=iksweb-git/assets/css/style.css?ver=iksweb-git/assets/js/script.js?ver=HTML / DOM Fingerprints
git-icondata-toggle="factory-tooltip"data-placement="right"APPLICATION