
MORKVA Vchasno Kasa Integration Security & Risk Analysis
wordpress.org/plugins/mrkv-vchasno-kasaПлагін інтеграції WooCommerce з Kasa.vchasno.com.ua, сервісом програмної реєстрації розрахункових операцій (пРРО).
Is MORKVA Vchasno Kasa Integration Safe to Use in 2026?
Generally Safe
Score 98/100MORKVA Vchasno Kasa Integration has a strong security track record. Known vulnerabilities have been patched promptly.
The "mrkv-vchasno-kasa" plugin v1.1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices in several key areas. All identified entry points, including AJAX handlers, have associated capability checks, and SQL queries are exclusively executed using prepared statements. The plugin also demonstrates diligent output escaping, with over 97% of outputs being properly sanitized. Furthermore, the absence of any critical or high-severity taint flows suggests that the code is likely resistant to common injection-based attacks.
However, there are notable concerns that temper the overall security assessment. The plugin has a history of two medium-severity vulnerabilities, both related to missing authorization. While there are currently no unpatched vulnerabilities, this pattern indicates a recurring issue that attackers could exploit if an unpatched version becomes available or if a new authorization flaw is introduced. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are not being used in a way that could be leveraged by an attacker, especially in conjunction with past authorization issues.
In conclusion, the plugin has made significant strides in secure coding, particularly with its handling of AJAX, SQL, and output. The complete lack of taint flows is a strong positive. Nevertheless, the historical pattern of missing authorization vulnerabilities is a significant red flag. Developers should prioritize a thorough review of all authorization checks to prevent future exploits. The plugin's strengths lie in its technical implementation of security controls, but its weakness lies in the historical assurance of proper authorization mechanisms.
Key Concerns
- History of 2 medium severity CVEs (Missing Authorization)
- File operations present
- External HTTP requests present
MORKVA Vchasno Kasa Integration Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Vchasno Kasa <= 1.0.3 - Unauthenticated Log File Clearing
Vchasno Kasa <= 1.0.3 - Missing Authorization to Unauthenticated Invoice Generation
MORKVA Vchasno Kasa Integration Code Analysis
Bundled Libraries
Output Escaping
MORKVA Vchasno Kasa Integration Attack Surface
AJAX Handlers 5
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
MORKVA Vchasno Kasa Integration Maintenance & Trust
Maintenance Signals
Community Trust
MORKVA Vchasno Kasa Integration Alternatives
Payment gateway – Robokassa for WooCommerce
wc-robokassa
Integration Robokassa in WooCommerce as payment gateway plugin.
Калькулятор стоимости доставки СДЭК для WooCommerce
cdek-delivery-calculator
Расчет стоимости доставки товара транспортной компанией СДЭК. Разработка и поддержка — компания Mint Studio
real.PostImages
real-postimages
Дополнительное поле записей (постов) для изображений. | English read below
Affiliate program for your website ( integration with Sdelka.biz )
affiliate-marketing
Плагин интегрирует ваш сайт с платформой партнёрского маркетинга Sdelka.biz.
Витрина товаров Glopart
product-widget-glopart
Теперь вы можете активно зарабатывать на продаже топовых товаров из каталога партнерских программ Glopart. Перейти на сайт Glopart.ru
MORKVA Vchasno Kasa Integration Developer Profile
14 plugins · 3K total installs
How We Detect MORKVA Vchasno Kasa Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mrkv-vchasno-kasa/classes//wp-content/plugins/mrkv-vchasno-kasa/assets/css//wp-content/plugins/mrkv-vchasno-kasa/assets/js//wp-content/plugins/mrkv-vchasno-kasa/assets/js/mrkv-vchasno-kasa.jsmrkv-vchasno-kasa/assets/css/mrkv-vchasno-kasa.css?ver=mrkv-vchasno-kasa/assets/js/mrkv-vchasno-kasa.js?ver=HTML / DOM Fingerprints
mrkv-vchasnokasa-noticemrkv_vchasno_ind_taxcodemrkv_vchasno_kasa_notice_nonce