Morkva quick order button Security & Risk Analysis

wordpress.org/plugins/morkva-buy-one-click

Add a "Buy in 1 click" button to WooCommerce product pages for faster checkout. Minimal form. Instant order. Clean UX.

0 active installs v0.2.7 PHP 7.4+ WP 5.2+ Updated Unknown
buy-nowone-click-checkoutquick-order
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Morkva quick order button Safe to Use in 2026?

Generally Safe

Score 100/100

Morkva quick order button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "morkva-buy-one-click" plugin v0.2.7 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin also implements a nonce check, which is a fundamental security practice for AJAX requests.

However, there are areas for improvement. The most significant concern is the lack of capability checks on the AJAX handlers. While there are no unauthenticated AJAX handlers, the absence of role-based access control means that any authenticated user, regardless of their privileges, can trigger these AJAX actions. This could lead to unintended consequences or privilege escalation if the AJAX actions themselves are not designed with strict internal validation. Additionally, 20% of output operations are not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data originates from user input.

The plugin's vulnerability history is completely clear, with no recorded CVEs. This suggests that the plugin has historically been well-maintained or has not been a significant target for attackers. However, this historical cleanliness does not guarantee future security. The combination of the current code analysis, particularly the missing capability checks and unescaped output, warrants careful consideration for any site using this plugin.

Key Concerns

  • Missing capability checks on AJAX handlers
  • Unescaped output (20% of outputs)
Vulnerabilities
None known

Morkva quick order button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Morkva quick order button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
120 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped150 total outputs
Attack Surface

Morkva quick order button Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_mrkv_buy_one_click__create_orderclasses\woocommerce\mrkv-buy-one-click-woocommerce.php:18
noprivwp_ajax_mrkv_buy_one_click__create_orderclasses\woocommerce\mrkv-buy-one-click-woocommerce.php:19

Shortcodes 1

[mrkv_buy_one_click] classes\controller\mrkv-buy-one-click-shortcodes.php:18
WordPress Hooks 9
actionwp_enqueue_scriptsclasses\controller\mrkv-buy-one-click-assets.php:18
actionwp_footerclasses\controller\mrkv-buy-one-click-shortcodes.php:52
actionadmin_enqueue_scriptsclasses\settings\admin\mrkv-buy-one-click-admin-assets.php:19
actionadmin_menuclasses\settings\admin\mrkv-buy-one-click-menu.php:25
actionadmin_initclasses\settings\global\mrkv-buy-one-click-options.php:19
actionwoocommerce_single_product_summaryclasses\woocommerce\mrkv-buy-one-click-woocommerce.php:21
actionwoocommerce_after_add_to_cart_buttonclasses\woocommerce\mrkv-buy-one-click-woocommerce.php:22
actionbefore_woocommerce_initmorkva-buy-one-click.php:24
actioninitmorkva-buy-one-click.php:53
Maintenance & Trust

Morkva quick order button Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads591

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Morkva quick order button Developer Profile

Ihor Kit

14 plugins · 3K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Morkva quick order button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/morkva-buy-one-click/assets/css/front/front-mrkv-buy-one-click.css/wp-content/plugins/morkva-buy-one-click/assets/js/front/front-buy-one-click.js/wp-content/plugins/morkva-buy-one-click/assets/css/front/front-mrkv-but-one-click-tel.css/wp-content/plugins/morkva-buy-one-click/assets/js/front/front-mrkv-but-one-click-tel.js/wp-content/plugins/morkva-buy-one-click/assets/js/front/utils.js/wp-content/plugins/morkva-buy-one-click/assets/css/admin/mrkv-buy-one-click.css/wp-content/plugins/morkva-buy-one-click/assets/js/admin/mrkv-buy-one-click.js
Script Paths
/wp-content/plugins/morkva-buy-one-click/assets/js/front/front-buy-one-click.js/wp-content/plugins/morkva-buy-one-click/assets/js/front/front-mrkv-but-one-click-tel.js/wp-content/plugins/morkva-buy-one-click/assets/js/front/utils.js/wp-content/plugins/morkva-buy-one-click/assets/js/admin/mrkv-buy-one-click.js
Version Parameters
morkva-buy-one-click/assets/css/front/front-mrkv-buy-one-click.css?ver=morkva-buy-one-click/assets/js/front/front-buy-one-click.js?ver=morkva-buy-one-click/assets/css/front/front-mrkv-but-one-click-tel.css?ver=morkva-buy-one-click/assets/js/front/front-mrkv-but-one-click-tel.js?ver=morkva-buy-one-click/assets/js/front/utils.js?ver=morkva-buy-one-click/assets/css/admin/mrkv-buy-one-click.css?ver=morkva-buy-one-click/assets/js/admin/mrkv-buy-one-click.js?ver=

HTML / DOM Fingerprints

CSS Classes
mrkv_buy-one-click__form__innermrkv_buy-one-click__open-callmrkv_buy-one-click__create_ordermrkv_buy-one-click__titlemrkv_buy-one-click__product__info
Data Attributes
mrkv_buy-one-click__usernamemrkv_buy-one-click__phone
JS Globals
mrkv_buy_one_click_helper
FAQ

Frequently Asked Questions about Morkva quick order button