
Morkva Plata by Mono Extended Security & Risk Analysis
wordpress.org/plugins/mrkv-monobank-extendedЕквайринг та Моно Чекаут в одному плагіні. У нас більше досвіду з інтернет магазинами на WooCommerce ніж у самого Монобанку ;)
Is Morkva Plata by Mono Extended Safe to Use in 2026?
Generally Safe
Score 100/100Morkva Plata by Mono Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mrkv-monobank-extended" plugin version 1.3.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in handling SQL queries, exclusively using prepared statements, which significantly mitigates SQL injection risks. Additionally, there is no recorded vulnerability history, suggesting a generally stable and well-maintained codebase in the past.
However, significant concerns arise from the attack surface analysis. A substantial number of AJAX handlers (10 out of 10) lack authentication checks, creating a wide entry point for potential unauthorized actions. Furthermore, the taint analysis reveals 4 flows with unsanitized paths, indicating a risk of insecure handling of user-supplied data. The low percentage of properly escaped output (18%) also raises alarms about potential cross-site scripting (XSS) vulnerabilities when displaying data that might originate from user input or external sources.
In conclusion, while the plugin avoids common pitfalls like raw SQL and has a clean vulnerability history, the absence of authentication on numerous AJAX endpoints and the presence of unsanitized data flows are critical security weaknesses. The poor output escaping further compounds these risks. The plugin's overall security is compromised by these vulnerabilities, requiring immediate attention to protect the WordPress site.
Key Concerns
- AJAX handlers without authentication checks
- Taint flows with unsanitized paths
- Low percentage of properly escaped output
- No nonce checks
Morkva Plata by Mono Extended Security Vulnerabilities
Morkva Plata by Mono Extended Code Analysis
Output Escaping
Data Flow Analysis
Morkva Plata by Mono Extended Attack Surface
AJAX Handlers 10
Shortcodes 4
WordPress Hooks 28
Maintenance & Trust
Morkva Plata by Mono Extended Maintenance & Trust
Maintenance Signals
Community Trust
Morkva Plata by Mono Extended Alternatives
Рекламная платформа Native Rent
nativerent
Релевантная реклама для ваших читателей. Рекламодатели сервиса платят в 2-3 раза больше за 1 тыс. показов страниц, чем привычные рекламные сетки.
Георгиевская ленточка для сайта
wp-lenta9may
Плагин выводит георгиевскую ленточку в левом углу вашего сайта на cms wordpress.
Bg Highlight Names
bg-highlight-names
Highlight the names in the text
real.PostImages
real-postimages
Дополнительное поле записей (постов) для изображений. | English read below
Affiliate program for your website ( integration with Sdelka.biz )
affiliate-marketing
Плагин интегрирует ваш сайт с платформой партнёрского маркетинга Sdelka.biz.
Morkva Plata by Mono Extended Developer Profile
14 plugins · 3K total installs
How We Detect Morkva Plata by Mono Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mrkv-monobank-extended/assets/css/monopay-setting-style.css/wp-content/plugins/mrkv-monobank-extended/assets/css/monopay-checkout.cssmrkv-monobank-extended/assets/css/monopay-setting-style.css?ver=mrkv-monobank-extended/assets/css/monopay-checkout.css?ver=HTML / DOM Fingerprints
monopay-checkout-button<!-- MonoCheckout order id: data-mono-checkout-product-iddata-mono-checkout-buttondata-mono-checkout-button-typemono_checkout_product_php