Karrya Field service management system Security & Risk Analysis

wordpress.org/plugins/karrya-field-service-management-system

Karrya is a simple Field service management system. Lead automation system that manages clients, quotations, invoicing and payments.

10 active installs v1.6.2 PHP + WP 5.0+ Updated Unknown
field-servicefield-service-managementkarryamanagement-systemservice-management
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Karrya Field service management system Safe to Use in 2026?

Generally Safe

Score 100/100

Karrya Field service management system has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "karrya-field-service-management-system" plugin v1.6.2 presents a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, along with a significant number of nonce and capability checks, there are significant concerns regarding its attack surface. A large number of AJAX handlers (14 out of 16) lack authentication checks, creating numerous potential entry points for attackers. This is further exacerbated by the taint analysis revealing a concerning number of flows with unsanitized paths, all of which are categorized as high severity. The plugin's history of zero known CVEs is a positive indicator, suggesting a potentially well-maintained codebase. However, the high severity taint flows, despite the lack of historical vulnerabilities, represent a clear and present risk that should not be overlooked.

Key Concerns

  • Large number of unprotected AJAX handlers
  • High severity unsanitized taint flows
Vulnerabilities
None known

Karrya Field service management system Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Karrya Field service management system Code Analysis

Dangerous Functions
0
Raw SQL Queries
18
196 prepared
Unescaped Output
94
1294 escaped
Nonce Checks
32
Capability Checks
10
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

92% prepared214 total queries

Output Escaping

93% escaped1388 total outputs
Data Flows
36 unsanitized

Data Flow Analysis

25 flows36 with unsanitized paths
search_sku (models\stock.php:268)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

Karrya Field service management system Attack Surface

Entry Points17
Unprotected14

AJAX Handlers 16

authwp_ajax_charge_insertcontrollers\leads.php:19
authwp_ajax_cost_insertcontrollers\leads.php:21
authwp_ajax_payment_insertcontrollers\leads.php:23
authwp_ajax_payment_deletecontrollers\leads.php:25
authwp_ajax_view_charge_blockcontrollers\leads.php:28
authwp_ajax_view_cost_blockcontrollers\leads.php:31
authwp_ajax_view_payment_blockcontrollers\leads.php:34
authwp_ajax_list_subdepartmentcontrollers\leads.php:36
authwp_ajax_send_invoice_to_customercontrollers\leads.php:39
authwp_ajax_send_quote_to_customercontrollers\leads.php:41
authwp_ajax_search_skucontrollers\leads.php:43
authwp_ajax_search_descriptioncontrollers\leads.php:44
authwp_ajax_get_sku_detailscontrollers\leads.php:46
noprivwp_ajax_list_subdepartmentcontrollers\shortcodes.php:7
noprivwp_ajax_lead_bookcontrollers\shortcodes.php:8
authwp_ajax_lead_bookcontrollers\shortcodes.php:9

Shortcodes 1

[fsms-lead-dep-booking] fsms_index.php:79
WordPress Hooks 5
actionadmin_enqueue_scriptscontrollers\leads.php:16
actionwp_enqueue_scriptscontrollers\leads.php:17
actioninitfsms_index.php:73
actionadmin_menufsms_index.php:75
filterplugin_action_linksfsms_index.php:99
Maintenance & Trust

Karrya Field service management system Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Karrya Field service management system Developer Profile

wapnishantha

4 plugins · 30 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Karrya Field service management system

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/karrya-field-service-management-system/assets/css/style.css/wp-content/plugins/karrya-field-service-management-system/assets/js/common.js/wp-content/plugins/karrya-field-service-management-system/assets/js/ajax.js
Script Paths
/wp-content/plugins/karrya-field-service-management-system/assets/js/common.js/wp-content/plugins/karrya-field-service-management-system/assets/js/ajax.js
Version Parameters
karrya-field-service-management-system/assets/css/style.css?v=1karrya-field-service-management-system/assets/js/common.js?ver=0.1.0karrya-field-service-management-system/assets/js/ajax.js?ver=0.1.0

HTML / DOM Fingerprints

JS Globals
fsms_i18nfsms_js_vars
Shortcode Output
[fsms-lead-dep-booking]
FAQ

Frequently Asked Questions about Karrya Field service management system