Morkva Liqpay Extended Security & Risk Analysis

wordpress.org/plugins/mrkv-liqpay-extended

Платіжний модуль LiqPay з callback.

400 active installs v0.8.6 PHP 7.1+ WP 5.2+ Updated Jan 29, 2026
%d0%bb%d0%b8%d0%ba%d0%bf%d0%b5%d0%b9%d0%bb%d1%96%d0%ba%d0%bf%d0%b5%d0%b9liqpay
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Morkva Liqpay Extended Safe to Use in 2026?

Generally Safe

Score 100/100

Morkva Liqpay Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The mrkv-liqpay-extended plugin v0.8.6 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and shows no recorded vulnerability history, the presence of four AJAX handlers without any authentication or authorization checks presents a significant attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure depending on their functionality. The taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity, warrants attention as these could potentially be exploited if they interact with user-supplied input. The plugin also has a 50% rate of properly escaped output, indicating that some data displayed to users may not be adequately sanitized, potentially opening the door for cross-site scripting (XSS) vulnerabilities. In conclusion, while the absence of known CVEs and robust SQL handling are positive signs, the lack of security checks on a substantial portion of its entry points is a critical weakness that elevates the risk profile of this plugin.

Key Concerns

  • AJAX handlers without authentication checks
  • Unsanitized paths in taint analysis flows
  • 50% of outputs not properly escaped
Vulnerabilities
None known

Morkva Liqpay Extended Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Morkva Liqpay Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
10 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

50% escaped20 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mrkv_liqpay_add_plugin_meta_box (includes\class-morkva-liqpay-orders.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Morkva Liqpay Extended Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_mrkv_liqpay_cancel_payment_holdincludes\class-morkva-liqpay-orders.php:21
noprivwp_ajax_mrkv_liqpay_cancel_payment_holdincludes\class-morkva-liqpay-orders.php:22
authwp_ajax_mrkv_liqpay_final_payment_holdincludes\class-morkva-liqpay-orders.php:24
noprivwp_ajax_mrkv_liqpay_final_payment_holdincludes\class-morkva-liqpay-orders.php:25
WordPress Hooks 13
actionadmin_menuincludes\class-morkva-liqpay-menu.php:21
actionadd_meta_boxesincludes\class-morkva-liqpay-orders.php:19
actioninitincludes\class-wc-gateway-morkva-liqpay.php:76
actionwoocommerce_update_options_payment_gatewaysincludes\class-wc-gateway-morkva-liqpay.php:77
filterwoocommerce_gateway_iconincludes\class-wc-gateway-morkva-liqpay.php:81
actionbefore_woocommerce_initmrkv-liqpay-extended.php:24
actionplugins_loadedmrkv-liqpay-extended.php:46
filterwoocommerce_payment_gatewaysmrkv-liqpay-extended.php:49
actionwoocommerce_blocks_loadedmrkv-liqpay-extended.php:52
actionplugins_loadedmrkv-liqpay-extended.php:55
actionadmin_enqueue_scriptsmrkv-liqpay-extended.php:58
actionwp_enqueue_scriptsmrkv-liqpay-extended.php:61
actionwoocommerce_blocks_payment_method_type_registrationmrkv-liqpay-extended.php:136
Maintenance & Trust

Morkva Liqpay Extended Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.1
Downloads7K

Community Trust

Rating100/100
Number of ratings9
Active installs400
Developer Profile

Morkva Liqpay Extended Developer Profile

Ihor Kit

14 plugins · 3K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Morkva Liqpay Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mrkv-liqpay-extended/css/morkva-liqpay-admin.css/wp-content/plugins/mrkv-liqpay-extended/js/admin/admin-mrkv-liqpay.js/wp-content/plugins/mrkv-liqpay-extended/css/morkva-liqpay-front.css
Script Paths
/wp-content/plugins/mrkv-liqpay-extended/js/admin/admin-mrkv-liqpay.js
Version Parameters
mrkv-liqpay-extended/css/morkva-liqpay-admin.css?ver=mrkv-liqpay-extended/js/admin/admin-mrkv-liqpay.js?ver=mrkv-liqpay-extended/css/morkva-liqpay-front.css?ver=

HTML / DOM Fingerprints

CSS Classes
morkva-liqpay-adminmorkva-liqpay-front
FAQ

Frequently Asked Questions about Morkva Liqpay Extended