Interface for Geniki Taxydromiki API v2 and Woo Security & Risk Analysis

wordpress.org/plugins/interface-for-geniki-taxydromiki-and-woo

Interface for Geniki Taxydromiki API v2 and Woocommerce.

50 active installs v1.0.2 PHP + WP 4.0+ Updated Jul 27, 2023
e-commerceecommerceshippingwoocommercewordpress-ecommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Interface for Geniki Taxydromiki API v2 and Woo Safe to Use in 2026?

Generally Safe

Score 85/100

Interface for Geniki Taxydromiki API v2 and Woo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The interface-for-geniki-taxydromiki-and-woo plugin v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The presence of nonce checks and a reasonable percentage of properly escaped output indicates a focus on preventing common web vulnerabilities. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its security. The lack of any recorded vulnerabilities or CVEs is also a positive indicator of past security diligence.

However, a key concern is the complete absence of capability checks. While the current static analysis doesn't reveal directly exploitable issues stemming from this, it represents a significant gap in authorization enforcement. If any of the plugin's functionalities were to be exposed through future changes or inadvertently become accessible via other means, the lack of capability checks could lead to unauthorized access or actions. The 64% proper output escaping, while not critically low, means that 36% of outputs are potentially vulnerable to cross-site scripting (XSS) if the data being output is user-controlled and not sufficiently sanitized elsewhere.

In conclusion, the plugin is built with several good security practices, notably in its handling of database queries and avoiding risky functions. The vulnerability history is clean, which is a strong positive. The primary weaknesses lie in the complete lack of capability checks, leaving authorization potentially unaddressed, and the proportion of unescaped output which presents a moderate XSS risk. Addressing these areas would significantly enhance the plugin's overall security.

Key Concerns

  • No capability checks implemented
  • 36% of outputs are not properly escaped
Vulnerabilities
None known

Interface for Geniki Taxydromiki API v2 and Woo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Interface for Geniki Taxydromiki API v2 and Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
21 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

64% escaped33 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ifgtapifwoo_getVouchersbyDate (options.php:151)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interface for Geniki Taxydromiki API v2 and Woo Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ifgtapifwoo-track-and-trace] track-and-trace.php:119
WordPress Hooks 13
filterbulk_actions-edit-shop_orderbulk-actions.php:5
filterhandle_bulk_actions-edit-shop_orderbulk-actions.php:19
actionadmin_print_stylesgeniki-metabox.php:6
actionadd_meta_boxes_shop_ordergeniki-metabox.php:19
actionsave_postgeniki-metabox.php:141
actionadmin_menuoptions.php:136
actionadmin_initoptions.php:137
actionadmin_post_download_vouchers_pdfoptions.php:150
filtermanage_edit-shop_order_columnsorders-column.php:9
actionadmin_print_stylesorders-column.php:25
actionmanage_shop_order_posts_custom_columnorders-column.php:58
actionadmin_enqueue_scriptswoocommerce-geniki.php:33
actionwoocommerce_thankyouwoocommerce-geniki.php:44
Maintenance & Trust

Interface for Geniki Taxydromiki API v2 and Woo Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 27, 2023
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Interface for Geniki Taxydromiki API v2 and Woo Developer Profile

Iraklis Kostalas

2 plugins · 150 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Interface for Geniki Taxydromiki API v2 and Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interface-for-geniki-taxydromiki-and-woo/css/geniki-taxydromiki-admin.css/wp-content/plugins/interface-for-geniki-taxydromiki-and-woo/css/geniki-taxydromiki-front.css
Script Paths
https://kit.fontawesome.com/56a47f9813.js
Version Parameters
interface-for-geniki-taxydromiki-and-woo/css/geniki-taxydromiki-admin.css?ver=interface-for-geniki-taxydromiki-and-woo/css/geniki-taxydromiki-front.css?ver=

HTML / DOM Fingerprints

CSS Classes
geniki_meta_box
Data Attributes
data-voucher-nodata-langdata-order-iddata-is-canceleddata-is-closed
Shortcode Output
<form method='GET' action=''><input type='text' name='voucher' placeholder='Voucher Number'/><input type='submit' value='Search Voucher'/></form>
FAQ

Frequently Asked Questions about Interface for Geniki Taxydromiki API v2 and Woo