Онлайн-магазин Мерчиум Security & Risk Analysis

wordpress.org/plugins/merchiumru

Полноценный интернет-магазин для вашего блога.

10 active installs v1.0.1 PHP + WP 3.6+ Updated Dec 29, 2015
cscart%d0%bc%d0%b0%d0%b3%d0%b0%d0%b7%d0%b8%d0%bdecommercefacebookmerchium%d1%8d%d0%bb%d0%b5%d0%ba%d1%82%d1%80%d0%be%d0%bd%d0%bd%d0%b0%d1%8f-%d0%ba%d0%be%d0%bc%d0%bc%d0%b5%d1%80%d1%86%d0%b8%d1%8f
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Онлайн-магазин Мерчиум Safe to Use in 2026?

Generally Safe

Score 85/100

Онлайн-магазин Мерчиум has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "merchiumru" v1.0.1 plugin exhibits a mixed security posture. While it shows strengths in its handling of SQL queries and lack of external HTTP requests, significant concerns arise from its attack surface and output escaping. The presence of three unprotected AJAX handlers presents a direct entry point for potential unauthenticated actions, a common vector for exploiting plugins. Furthermore, only 10% of output is properly escaped, suggesting a high risk of cross-site scripting (XSS) vulnerabilities where user-supplied data could be injected into the frontend without proper sanitization.

The taint analysis, while not revealing critical or high severity issues, did identify two flows with unsanitized paths, which, combined with the unprotected AJAX endpoints, could potentially lead to exploitable conditions if these paths involve user-controlled input. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign indicating a lack of publicly known exploits. However, this does not mitigate the risks identified in the static analysis.

In conclusion, the plugin's lack of known vulnerabilities is a strength, but it is overshadowed by critical weaknesses in its attack surface management and output sanitization. The three unprotected AJAX handlers and the severely limited output escaping are the most pressing security concerns and require immediate attention to improve the plugin's overall security posture. The taint analysis results further underscore the need for better input sanitization.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • No nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

Онлайн-магазин Мерчиум Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Онлайн-магазин Мерчиум Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped20 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
merchium_ajax_request (php\fn.core.php:293)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Онлайн-магазин Мерчиум Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_merchium_hide_vote_messagemerchium.php:41
authwp_ajax_merchium_formmerchium.php:45
noprivwp_ajax_merchium_formmerchium.php:46

Shortcodes 1

[merchium_store] merchium.php:50
WordPress Hooks 17
actionadmin_menumerchium.php:37
actionadmin_initmerchium.php:38
actionadmin_enqueue_scriptsmerchium.php:39
actionadmin_noticesmerchium.php:40
filterplugin_action_links_merchium_wp/merchium.phpmerchium.php:42
actionpre_update_option_merchium_widget_codemerchium.php:43
actionsm_buildmapmerchium.php:44
actionwp_titlemerchium.php:51
actionwp_headmerchium.php:52
actionwp_enqueue_scriptsmerchium.php:53
actionwpmerchium.php:56
actionplugins_loadedmerchium.php:57
actionwp_titlemerchium.php:58
actionwp_headmerchium.php:59
actionplugins_loadedmerchium.php:64
filteraioseop_titlephp\fn.compatibility.php:52
filteraioseop_descriptionphp\fn.compatibility.php:53
Maintenance & Trust

Онлайн-магазин Мерчиум Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedDec 29, 2015
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Онлайн-магазин Мерчиум Developer Profile

merchium

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Онлайн-магазин Мерчиум

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/merchiumru/css/admin.css/wp-content/plugins/merchiumru/css/admin-3.8.css/wp-content/plugins/merchiumru/js/admin.js/wp-content/plugins/merchiumru/css/frontend.css
Script Paths
/wp-content/plugins/merchiumru/js/admin.js/wp-content/plugins/merchiumru/js/frontend-fragment.js

HTML / DOM Fingerprints

HTML Comments
<!-- Merchium code. Please do not remove this line or your Merchium shopping cart will not work properly. --><!-- Merchium code end -->
JS Globals
merchium_opts
Shortcode Output
[merchium_store]
FAQ

Frequently Asked Questions about Онлайн-магазин Мерчиум