
Онлайн-магазин Мерчиум Security & Risk Analysis
wordpress.org/plugins/merchiumruПолноценный интернет-магазин для вашего блога.
Is Онлайн-магазин Мерчиум Safe to Use in 2026?
Generally Safe
Score 85/100Онлайн-магазин Мерчиум has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "merchiumru" v1.0.1 plugin exhibits a mixed security posture. While it shows strengths in its handling of SQL queries and lack of external HTTP requests, significant concerns arise from its attack surface and output escaping. The presence of three unprotected AJAX handlers presents a direct entry point for potential unauthenticated actions, a common vector for exploiting plugins. Furthermore, only 10% of output is properly escaped, suggesting a high risk of cross-site scripting (XSS) vulnerabilities where user-supplied data could be injected into the frontend without proper sanitization.
The taint analysis, while not revealing critical or high severity issues, did identify two flows with unsanitized paths, which, combined with the unprotected AJAX endpoints, could potentially lead to exploitable conditions if these paths involve user-controlled input. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign indicating a lack of publicly known exploits. However, this does not mitigate the risks identified in the static analysis.
In conclusion, the plugin's lack of known vulnerabilities is a strength, but it is overshadowed by critical weaknesses in its attack surface management and output sanitization. The three unprotected AJAX handlers and the severely limited output escaping are the most pressing security concerns and require immediate attention to improve the plugin's overall security posture. The taint analysis results further underscore the need for better input sanitization.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks on AJAX
- No capability checks
Онлайн-магазин Мерчиум Security Vulnerabilities
Онлайн-магазин Мерчиум Code Analysis
Output Escaping
Data Flow Analysis
Онлайн-магазин Мерчиум Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Онлайн-магазин Мерчиум Maintenance & Trust
Maintenance Signals
Community Trust
Онлайн-магазин Мерчиум Alternatives
Social Shop for WooCommerce
facebook-shop-by-storeyacom
This plugin will import your Woocommerce store to Facebook in a couple of minutes, with no development or design skills required.
Social Commerce for WooCommerce
woo-to-facebook-shop
Now you can start your facebook shop free. With Social Commerce for WooCommerce plugin you can easily sync or unsync your products from your woocommer …
Easy Pixels CF7 extension
easy-pixels-contact-form-extension-by-jevnet
"Easy Pixels CF7" is the "Easy Pixels" plugin extension to set the tracking codes when a Contact Form 7 is sent.
Easy Pixels eCommerce extension
easy-pixels-ecommerce-extension-by-jevnet
"Easy Pixels for Woocommerce" is the "Easy Pixels" plugin extension to set the tracking codes on WooCommerce.
Meta Pixel Event Tracker for WooCommerce
meta-pixel-event-tracker
Adds customizable Meta Pixel event tracking support to WooCommerce.
Онлайн-магазин Мерчиум Developer Profile
2 plugins · 20 total installs
How We Detect Онлайн-магазин Мерчиум
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/merchiumru/css/admin.css/wp-content/plugins/merchiumru/css/admin-3.8.css/wp-content/plugins/merchiumru/js/admin.js/wp-content/plugins/merchiumru/css/frontend.css/wp-content/plugins/merchiumru/js/admin.js/wp-content/plugins/merchiumru/js/frontend-fragment.jsHTML / DOM Fingerprints
<!-- Merchium code. Please do not remove this line or your Merchium shopping cart will not work properly. --><!-- Merchium code end -->merchium_opts[merchium_store]