T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Security & Risk Analysis

wordpress.org/plugins/kolaykimlik

TC kimlik onayı ve Vergi Numarası onayı ile kullanıcı kayıtları, ödeme işlemleri ve çeşitli form eklentileri (Contact Form, NinjaForms, WPForms) kulla …

80 active installs v1.4.1 PHP 7.4+ WP 5.9+ Updated Aug 17, 2022
kimliktcvergino
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Safe to Use in 2026?

Generally Safe

Score 85/100

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'kolaykimlik' v1.4.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, or file operations, coupled with a high percentage of properly escaped output, suggests good development practices. Furthermore, the lack of any known CVEs or past vulnerabilities is a significant positive indicator. The attack surface is remarkably clean, with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Taint analysis revealing no unsanitized paths further strengthens this positive assessment.

However, a notable concern is the complete absence of nonce checks and capability checks across all code signals. While the current attack surface is zero, this indicates a potential weakness if new entry points were to be introduced or if existing code was modified without proper security awareness. The lack of any vulnerability history, while generally positive, also means there's no established track record of how the plugin handles security issues or if it has been rigorously tested against a wide range of attacks.

In conclusion, 'kolaykimlik' v1.4.1 appears to be a very secure plugin with excellent coding practices in place, particularly regarding input sanitization and SQL query security. The primary area for improvement and a point of caution is the lack of explicit nonce and capability checks, which, while not a direct vulnerability in the current state, represents a missed opportunity for robust access control that could leave the plugin susceptible to future threats.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Release Timeline

v1.3.3
Code Analysis
Analyzed Mar 16, 2026

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
91 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped96 total outputs
Attack Surface

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwpcf7_initincludes\class-kk-contactform-seven.php:6
filterwpcf7_validate_tc_kimlik*includes\class-kk-contactform-seven.php:7
filterwpcf7_messagesincludes\class-kk-contactform-seven.php:8
actionwpcf7_admin_initincludes\class-kk-contactform-seven.php:9
filterninja_forms_submit_dataincludes\class-kk-ninjaform.php:6
actionadmin_menuincludes\class-kk-tcinputsettings.php:4
actionadmin_initincludes\class-kk-tcinputsettings.php:5
filterplugin_action_linksincludes\class-kk-tcinputsettings.php:6
filterwoocommerce_checkout_fieldsincludes\class-kk-woocheckout.php:10
actionwoocommerce_after_checkout_validationincludes\class-kk-woocheckout.php:11
actionwoocommerce_admin_order_data_after_billing_addressincludes\class-kk-woocheckout.php:12
Maintenance & Trust

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedAug 17, 2022
PHP min version7.4
Downloads7K

Community Trust

Rating60/100
Number of ratings2
Active installs80
Developer Profile

T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama Developer Profile

Fuat POYRAZ

3 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/kolaykimlik/appsero/src/Client.php

HTML / DOM Fingerprints

CSS Classes
wpcf7-tcwpcf7-surname_of_t_cwpcf7-year_of_t_c
Data Attributes
name="name_of_t_c"name="surname_of_t_c"name="year_of_t_c"
Shortcode Output
<label>Ad (required)</label><label> Soyad (required)</label><label> Doğum Yılı (required)</label>
FAQ

Frequently Asked Questions about T.C Kimlik & Vergi No Dogrulama – Kolay Kimlik Doğrulama