KASSA.AT For WooCommerce Security & Risk Analysis

wordpress.org/plugins/kassa-at-for-woocommerce

This Plugin makes a connection to your KASSA.AT account to automate your experiences and synchronize stocks between physical-store and onlineshop.

0 active installs v1.1.1 PHP 7.0.33+ WP 5.7+ Updated Apr 22, 2024
kassa-atkasse-prostockstock-managementwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is KASSA.AT For WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

KASSA.AT For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "kassa-at-for-woocommerce" plugin v1.1.1 exhibits a concerning security posture primarily due to its extensive unprotected attack surface. All 14 identified AJAX handlers lack authentication checks, presenting a significant risk of unauthorized access and execution of plugin functions. While the code signals indicate strong practices regarding SQL queries and output escaping, the absence of nonces and capability checks on these numerous entry points is a critical oversight. The taint analysis also revealed a substantial number of flows with unsanitized paths, although no critical or high severity issues were flagged in this specific scan.

The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator and suggests that, to date, no publicly known vulnerabilities have been exploited or discovered. However, the lack of historical issues should not be interpreted as a guarantee of current security, especially given the identified weaknesses in the code analysis. The strong adherence to prepared statements for SQL and proper output escaping are commendable best practices. Nevertheless, the overwhelming reliance on unprotected AJAX handlers overshadows these strengths, creating a substantial risk profile.

In conclusion, while the plugin demonstrates good practices in database interaction and output handling, its security is significantly compromised by the unprotected AJAX endpoints. The high number of unsanitized taint flows is also a point of concern, even without direct critical or high severity findings in this analysis. Users should be aware of the potential for attackers to exploit these unprotected entry points. The absence of historical vulnerabilities is positive but does not mitigate the immediate risks identified in the static and taint analysis.

Key Concerns

  • 14 unprotected AJAX handlers
  • 8 flows with unsanitized paths
  • Only 4 nonce checks for 14 entry points
  • Only 2 capability checks for 14 entry points
Vulnerabilities
None known

KASSA.AT For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

KASSA.AT For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
224 escaped
Nonce Checks
4
Capability Checks
2
File Operations
18
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped224 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

14 flows8 with unsanitized paths
kaw_maybe_save_data (create-menus.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

KASSA.AT For WooCommerce Attack Surface

Entry Points14
Unprotected14

AJAX Handlers 14

authwp_ajax_kaw_delete_connectioncreate-menus.php:160
authwp_ajax_kaw_reload_log_filecreate-menus.php:173
authwp_ajax_kaw_activate_loggingkassa-at-for-woocommerce.php:204
authwp_ajax_kaw_logfile_change_sizekassa-at-for-woocommerce.php:232
authwp_ajax_kaw_delete_logfilekassa-at-for-woocommerce.php:261
authwp_ajax_my_dismiss_noticekassa-at-for-woocommerce.php:361
authwp_ajax_kaw_activate_synchro_optionstock-syncro.php:56
authwp_ajax_kaw_delete_connectiontrunk\create-menus.php:160
authwp_ajax_kaw_reload_log_filetrunk\create-menus.php:173
authwp_ajax_kaw_activate_loggingtrunk\kassa-at-for-woocommerce.php:204
authwp_ajax_kaw_logfile_change_sizetrunk\kassa-at-for-woocommerce.php:232
authwp_ajax_kaw_delete_logfiletrunk\kassa-at-for-woocommerce.php:261
authwp_ajax_my_dismiss_noticetrunk\kassa-at-for-woocommerce.php:361
authwp_ajax_kaw_activate_synchro_optiontrunk\stock-syncro.php:56
WordPress Hooks 12
actionadmin_menucreate-menus.php:44
actionplugins_loadedkassa-at-for-woocommerce.php:269
actionadmin_noticeskassa-at-for-woocommerce.php:353
actionwoocommerce_reduce_order_stockstock-syncro.php:155
actionwoocommerce_before_single_productstock-syncro.php:255
actionwoocommerce_before_cart_tablestock-syncro.php:303
actionadmin_menutrunk\create-menus.php:44
actionplugins_loadedtrunk\kassa-at-for-woocommerce.php:269
actionadmin_noticestrunk\kassa-at-for-woocommerce.php:353
actionwoocommerce_reduce_order_stocktrunk\stock-syncro.php:155
actionwoocommerce_before_single_producttrunk\stock-syncro.php:255
actionwoocommerce_before_cart_tabletrunk\stock-syncro.php:303
Maintenance & Trust

KASSA.AT For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 22, 2024
PHP min version7.0.33
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

KASSA.AT For WooCommerce Developer Profile

brandonpirk

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KASSA.AT For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kassa-at-for-woocommerce/css/style.css/wp-content/plugins/kassa-at-for-woocommerce/js/script.js
Script Paths
/wp-content/plugins/kassa-at-for-woocommerce/js/script.js
Version Parameters
kassa-at-for-woocommerce/css/style.css?ver=kassa-at-for-woocommerce/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- NOTE: The term "kaw" is for "kassa at woocommerce" and will be a prefix for all functions created by this plugin! -->
JS Globals
kaw_enable_logkaw_activate_logging
REST Endpoints
/wp-json/kaw/
FAQ

Frequently Asked Questions about KASSA.AT For WooCommerce