muv – Kundenkonto Security & Risk Analysis

wordpress.org/plugins/muv-kundenkonto

Dieses Plugin erweitert Ihren Internet-Auftritt um die Möglichkeit, Ihren Kunden ein Kundenkonto anzubieten. Kunden können sich registrieren, anmelden …

10 active installs v1.5.0 PHP + WP 4.7+ Updated Sep 26, 2017
frontendkontokundenloginpasswort
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is muv – Kundenkonto Safe to Use in 2026?

Generally Safe

Score 85/100

muv – Kundenkonto has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The muv-kundenkonto v1.5.0 plugin exhibits a generally good security posture based on the static analysis. The absence of critical or high severity taint flows, along with 100% of SQL queries using prepared statements, indicates a strong focus on preventing common database-related vulnerabilities. Furthermore, the plugin demonstrates good practice by implementing capability checks and a nonce check, safeguarding against unauthorized actions. The limited external HTTP request is also a positive sign. However, a potential area of concern is the output escaping. With approximately 31% of outputs not being properly escaped, there's a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is directly reflected in the output without sufficient sanitization. The presence of 6 shortcodes, while not inherently insecure, represents a larger attack surface compared to plugins with fewer entry points, and it's crucial that these are handled with robust input validation and output escaping. The plugin's vulnerability history being clean is a significant strength, suggesting a history of secure development. Overall, the plugin has a solid foundation, but the unescaped output is the most prominent risk that warrants attention.

Key Concerns

  • Unescaped output found
  • Multiple shortcodes increase attack surface
Vulnerabilities
None known

muv – Kundenkonto Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

muv – Kundenkonto Release Timeline

v1.5.0Current
v1.0.1
v1.0.0
v0.5.2
v0.5.1
v0.5.0
Code Analysis
Analyzed Apr 16, 2026

muv – Kundenkonto Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
115 prepared
Unescaped Output
52
116 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared115 total queries

Output Escaping

69% escaped168 total outputs
Attack Surface

muv – Kundenkonto Attack Surface

Entry Points6
Unprotected0

Shortcodes 6

[muv-kk-kunde-ist-angemeldet] includes/muv/KundenKonto/Frontend/Shortcodes.php:17
[muv-kk-kunde-vorname] includes/muv/KundenKonto/Frontend/Shortcodes.php:18
[muv-kk-kunde-nachname] includes/muv/KundenKonto/Frontend/Shortcodes.php:19
[muv-kk-aendere-pwt] includes/muv/KundenKonto/Frontend/Shortcodes.php:20
[muv-kk-aendere-email] includes/muv/KundenKonto/Frontend/Shortcodes.php:21
[muv-kk-loesche-konto] includes/muv/KundenKonto/Frontend/Shortcodes.php:22
WordPress Hooks 23
actionadmin_menuincludes/muv/KundenKonto/Admin/Main.php:17
actionadmin_print_scriptsincludes/muv/KundenKonto/Admin/Main.php:20
actionadmin_initincludes/muv/KundenKonto/Admin/Settings/API.php:17
actionadmin_menuincludes/muv/KundenKonto/Admin/Settings/API.php:19
actionadmin_noticesincludes/muv/KundenKonto/Admin/Settings/API.php:23
actionadmin_initincludes/muv/KundenKonto/Admin/Settings/Allgemein.php:16
actionadmin_initincludes/muv/KundenKonto/Admin/Settings/Benachrichtigungen.php:33
actionadmin_initincludes/muv/KundenKonto/Admin/Settings/Benachrichtigungen.php:36
actionadmin_initincludes/muv/KundenKonto/Admin/Settings/EMail.php:18
actioninitincludes/muv/KundenKonto/Frontend/Login.php:16
filtertemplate_redirectincludes/muv/KundenKonto/Frontend/Login.php:21
actioninitincludes/muv/KundenKonto/Frontend/Logout.php:15
filtertemplate_redirectincludes/muv/KundenKonto/Frontend/Logout.php:20
actionwp_enqueue_scriptsincludes/muv/KundenKonto/Frontend/Main.php:25
filterwp_mail_content_typeincludes/muv/KundenKonto/Lib/Mail.php:35
actionphpmailer_initincludes/muv/KundenKonto/Lib/Mail.php:36
filterwp_mail_fromincludes/muv/KundenKonto/Lib/Mail.php:38
filterwp_mail_from_nameincludes/muv/KundenKonto/Lib/Mail.php:41
actionmuv-kk-cron-delete-accountsincludes/muv/KundenKonto/Plugin/Cron.php:16
actioninitincludes/muv/KundenKonto/Plugin/Main.php:15
actionwpmu_new_blogmuv-kundenkonto.php:103
actiondelete_blogmuv-kundenkonto.php:107
actionplugins_loadedmuv-kundenkonto.php:118

Scheduled Events 1

muv-kk-cron-delete-accounts
Maintenance & Trust

muv – Kundenkonto Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 26, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

muv – Kundenkonto Developer Profile

Meins und Vogel (muv)

3 plugins · 120 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect muv – Kundenkonto

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/muv-kundenkonto/vendor/public/font-awesome/css/font-awesome.min.css/wp-content/plugins/muv-kundenkonto/vendor/public/tipso/src/tipso.min.css/wp-content/plugins/muv-kundenkonto/vendor/public/tipso/src/tipso.min.js/wp-content/plugins/muv-kundenkonto/vendor/public/datatables.net/js/jquery.dataTables.min.js/wp-content/plugins/muv-kundenkonto/vendor/public/datatables.net-dt/css/jquery.dataTables.min.css/wp-content/plugins/muv-kundenkonto/assets/js/admin-common.js/wp-content/plugins/muv-kundenkonto/assets/css/admin-common.css/wp-content/plugins/muv-kundenkonto/assets/css/admin.css+3 more
Script Paths
/wp-content/plugins/muv-kundenkonto/vendor/public/tipso/src/tipso.min.js/wp-content/plugins/muv-kundenkonto/vendor/public/datatables.net/js/jquery.dataTables.min.js/wp-content/plugins/muv-kundenkonto/assets/js/admin-common.js/wp-content/plugins/muv-kundenkonto/assets/js/admin.js

HTML / DOM Fingerprints

CSS Classes
wp-menu-separator
HTML Comments
Zugriff nur als Plugin innerhalb von Wordpress benötigte Konstanten die interne Version-Nummer Der Dateiname (inkl. Pfad) +10 more
Data Attributes
data-muv-kk-id
JS Globals
MUV_KK_URLMUV_KK_NETWORK_ACTIVATED
Shortcode Output
[muv_kundenkonto_registrierung][muv_kundenkonto_anmeldung][muv_kundenkonto_logout][muv_kundenkonto_profil]
FAQ

Frequently Asked Questions about muv – Kundenkonto