Keskintech Marketplaces Security & Risk Analysis

wordpress.org/plugins/keskintech-marketplaces

Sync WooCommerce products, orders and stock with online marketplaces via real-time API or XLSX/CSV template export — all from one panel.

0 active installs v1.1 PHP 7.4+ WP 6.0+ Updated Mar 28, 2026
marketplaceorder-syncproduct-syncwoocommercewoocommerce-integration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Keskintech Marketplaces Safe to Use in 2026?

Generally Safe

Score 100/100

Keskintech Marketplaces has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "keskintech-marketplaces" plugin v1.1 exhibits a generally good security posture with strong adherence to best practices in several key areas. The complete absence of raw SQL queries, with all 161 utilizing prepared statements, and the 100% proper output escaping for 1355 outputs are significant strengths, indicating robust protection against common injection and XSS vulnerabilities. Furthermore, the presence of 37 nonce checks and 4 capability checks suggests an effort to secure entry points. The vulnerability history being completely clean further reinforces this positive impression, suggesting a well-maintained and secure codebase.

However, the static analysis reveals a notable concern: 23 out of 26 analyzed taint flows have unsanitized paths, with one identified as high severity. This indicates that user-controlled input within these flows may not be adequately validated or neutralized before being processed, potentially leading to unintended consequences or exploitation, despite the apparent lack of direct SQL injection or XSS issues in the final output. While the attack surface is small with only one unprotected entry point, the internal handling of data within these flows warrants close attention. The plugin also bundles the Select2 library, which, if outdated, could introduce vulnerabilities, though no specific version information is provided.

In conclusion, "keskintech-marketplaces" v1.1 demonstrates a strong foundation in security through its handling of SQL and output, and its clean vulnerability history is a testament to its stability. Nevertheless, the high number of unsanitized taint flows, particularly the one marked as high severity, represents a significant potential risk that needs to be addressed. The potential risk associated with the bundled Select2 library should also be investigated.

Key Concerns

  • High severity taint flow with unsanitized path
  • Large number of flows with unsanitized paths
  • Bundled library (Select2) potential risk
Vulnerabilities
None known

Keskintech Marketplaces Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Keskintech Marketplaces Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

Keskintech Marketplaces Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
161 prepared
Unescaped Output
6
1349 escaped
Nonce Checks
37
Capability Checks
4
File Operations
38
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared161 total queries

Output Escaping

100% escaped1355 total outputs
Data Flows · Security
23 unsanitized

Data Flow Analysis

25 flows23 with unsanitized paths
handle_save_order_cron (src/Admin/Pages/CronJobs/KTMP_Cron_Jobs_Page.php:556)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Keskintech Marketplaces Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ktmp_ajaxsrc/Admin/KTMP_Ajax.php:11
WordPress Hooks 43
actionbefore_delete_postfunctions.php:10
actionwoocommerce_delete_product_variationfunctions.php:15
actionwoocommerce_variation_optionsfunctions.php:27
actionwoocommerce_save_product_variationfunctions.php:39
actionwoocommerce_product_after_variable_attributesfunctions.php:68
actionwoocommerce_save_product_variationfunctions.php:93
actiondelete_attachmentfunctions.php:126
actionadmin_initfunctions.php:151
actionwoocommerce_product_options_general_product_datafunctions.php:222
actionwoocommerce_process_product_metafunctions.php:237
actionwoocommerce_variation_optionsfunctions.php:272
actionwoocommerce_save_product_variationfunctions.php:287
filtermanage_woocommerce_page_wc-orders_columnsfunctions.php:299
actionmanage_woocommerce_page_wc-orders_custom_columnfunctions.php:315
actionpre_update_option_ktmp_activation_codefunctions.php:401
actionktmp_retry_update_activationfunctions.php:406
actionadmin_enqueue_scriptsincludes/core/loader.php:21
actionplugins_loadedincludes/core/loader.php:86
actionadmin_noticeskeskintech-marketplaces.php:24
actionadmin_noticeskeskintech-marketplaces.php:36
actionadmin_initkeskintech-marketplaces.php:50
actionplugins_loadedkeskintech-marketplaces.php:79
actionbefore_woocommerce_initkeskintech-marketplaces.php:89
actioninitsrc/Admin/KTMP_Admin_Menu.php:51
actionadmin_menusrc/Admin/KTMP_Admin_Menu.php:158
actionaction_scheduler_initsrc/Cron/TaskEngine.php:16
actionktmp_handle_task_enginesrc/Cron/TaskEngine.php:18
actionktmp_transaction_handlersrc/Cron/TaskEngine.php:19
actionktmp_cron_jobsrc/Cron/TaskEngine.php:20
actionktmp_transaction_cleanersrc/Cron/TaskEngine.php:21
actionktmp_delete_old_logssrc/Cron/TaskEngine.php:22
actionktmp_delete_tmp_filessrc/Cron/TaskEngine.php:23
actionwoocommerce_before_attribute_deletesrc/Match/MatchCleanupHooks.php:9
actionpre_delete_termsrc/Match/MatchCleanupHooks.php:10
actionupdate_option_ktmp_brand_termsrc/Match/MatchCleanupHooks.php:11
actionupdate_option_ktmp_fixed_brandsrc/Match/MatchCleanupHooks.php:12
actionedit_termsrc/Match/MatchCleanupHooks.php:13
actioncreated_termsrc/Match/MatchCleanupHooks.php:14
actionpre_delete_termsrc/Match/MatchCleanupHooks.php:15
filterposts_clausessrc/Product/ProductFormHandler.php:246
filterwoocommerce_email_enabled_new_ordersrc/Transaction/Process/Order/OrderProcessor.php:53
filterwoocommerce_email_enabled_customer_refunded_ordersrc/Transaction/Process/Order/OrderProcessor.php:54
filterwoocommerce_email_enabled_cancelled_ordersrc/Transaction/Process/Order/OrderProcessor.php:55

Scheduled Events 2

ktmp_delete_old_logs
ktmp_delete_tmp_files
Maintenance & Trust

Keskintech Marketplaces Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 28, 2026
PHP min version7.4
Downloads701

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Keskintech Marketplaces Developer Profile

Keskintech

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Keskintech Marketplaces

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/keskintech-marketplaces/assets/css/admin-style.min.css/wp-content/plugins/keskintech-marketplaces/assets/js/keskintech-marketplaces.min.js/wp-content/plugins/keskintech-marketplaces/assets/js/marketplace-edit.min.js
Script Paths
/wp-content/plugins/keskintech-marketplaces/assets/js/keskintech-marketplaces.min.js/wp-content/plugins/keskintech-marketplaces/assets/js/marketplace-edit.min.js
Version Parameters
keskintech-marketplaces/assets/css/admin-style.min.css?ver=keskintech-marketplaces/assets/js/keskintech-marketplaces.min.js?ver=keskintech-marketplaces/assets/js/marketplace-edit.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
/* Feratlar ve Rubutlar Giremez ! */
Data Attributes
ktmp_marketplace_edit_obj
JS Globals
ktmp_marketplace_edit_obj
FAQ

Frequently Asked Questions about Keskintech Marketplaces