Kargo Takip Security & Risk Analysis

wordpress.org/plugins/kargo-takip

Müşterilerinizin kargolarını takip etmesine olanak sağlayan bir kargo takip eklentisidir. Kargo takip eklentisi aras kargo, mng kargo , sürat kargo ve …

50 active installs v1.2 PHP + WP 4.0+ Updated Unknown
aras-kargokargokargo-takipyurt-ici-kargoyurtici-kargo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Kargo Takip Safe to Use in 2026?

Generally Safe

Score 100/100

Kargo Takip has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "kargo-takip" plugin v1.2 demonstrates a generally strong security posture with no recorded vulnerabilities and diligent use of prepared statements for SQL queries. The analysis shows a low attack surface with no unprotected entry points, and the presence of nonce and capability checks, which are good security practices. However, a significant concern arises from the code signals: only 2% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealed a flow with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, warrants attention as it could be a precursor to path traversal or other file-related exploits if not properly handled. The lack of past vulnerabilities is positive but does not negate the immediate risks identified in the static analysis. Overall, while the plugin has strengths in its handling of SQL and entry points, the poor output escaping and the unsanitized path flow are critical weaknesses that significantly elevate the risk profile.

Key Concerns

  • Poor output escaping (2%)
  • Flow with unsanitized paths
Vulnerabilities
None known

Kargo Takip Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kargo Takip Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
112
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

2% escaped114 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<decodeandview> (ui\decodeandview.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Kargo Takip Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[aras_kargo_takip] kargo-takip.php:327
[yk_kargo_takip] kargo-takip.php:360
[mng_kargo_takip] kargo-takip.php:393
[surat_kargo_takip] kargo-takip.php:425
WordPress Hooks 9
actionadmin_menukargo-takip.php:12
actionadmin_initkargo-takip.php:18
actionadd_meta_boxeskargo-takip.php:95
actionsave_postkargo-takip.php:194
filtermanage_edit-shop_order_columnskargo-takip.php:196
actionmanage_shop_order_posts_custom_columnkargo-takip.php:205
actionadmin_enqueue_scriptskargo-takip.php:249
actionwoocommerce_order_items_tablekargo-takip.php:253
actionwp_enqueue_scriptskargo-takip.php:260
Maintenance & Trust

Kargo Takip Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedUnknown
PHP min version
Downloads7K

Community Trust

Rating60/100
Number of ratings2
Active installs50
Developer Profile

Kargo Takip Developer Profile

bytuncay

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kargo Takip

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kargo-takip/ui/js/tb_window.js

HTML / DOM Fingerprints

HTML Comments
<!-- Kargo numarası girilmişse sipariş durumunu otomatik olarak tamamlandı yapar -->
Data Attributes
name="kargo_takip_no"name="kargo_firmasi"value="<?php echo get_option("kt_api_url");?>"name="kt_api_url"value="<?php echo get_option("kt_api_user");?>"name="kt_api_user"+12 more
FAQ

Frequently Asked Questions about Kargo Takip