Na splátkyTB Security & Risk Analysis

wordpress.org/plugins/na-splatky-tb

Plugin Tatra banka Na splátky Vám umožní zobraziť možnosti nákupu na splátky formou ďalšej platobnej metódy vo Vašom WooCommerce e-shope.

0 active installs v1.0.7 PHP 7.0+ WP 5.0+ Updated Mar 19, 2022
nasplatkypaymentstatrabankawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Na splátkyTB Safe to Use in 2026?

Generally Safe

Score 85/100

Na splátkyTB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "na-splatky-tb" plugin v1.0.7 exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high-severity code signals, dangerous functions, or taint flows. The plugin exclusively uses prepared statements for its SQL queries, which is a significant security advantage. Furthermore, a high percentage of output is properly escaped, and nonce checks are present, mitigating common web vulnerabilities.

However, there are some areas for potential improvement. The complete absence of capability checks is a notable concern, as it suggests that any user, regardless of their role or permissions, could potentially interact with the plugin's functionalities. While no vulnerabilities are currently recorded in its history, this lack of historical data might not guarantee future safety. The plugin's minimal attack surface (0 entry points) is positive, but the lack of authenticated access controls on these potential points is a weakness that should be addressed.

In conclusion, "na-splatky-tb" v1.0.7 demonstrates good adherence to basic secure coding practices like prepared statements and output escaping. The absence of known vulnerabilities and critical code signals is reassuring. The primary area of concern is the lack of capability checks, which presents a theoretical risk of unauthorized access if any functionalities were to be exposed, even if currently none are identified. Overall, it appears to be a relatively secure plugin, but further hardening through capability checks would enhance its security further.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Na splátkyTB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Na splátkyTB Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
55 escaped
Nonce Checks
4
Capability Checks
0
File Operations
2
External Requests
4
Bundled Libraries
0

Output Escaping

83% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
init (includes\class-plugin.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Na splátkyTB Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
filterwc_get_price_decimalsincludes\class-client.php:85
actionwp_enqueue_scriptsincludes\class-frontend.php:10
filterwoocommerce_gateway_iconincludes\class-frontend.php:37
filterwoocommerce_checkout_after_order_reviewincludes\class-frontend.php:45
filterwoocommerce_after_add_to_cart_buttonincludes\class-frontend.php:54
filterwoocommerce_add_to_cart_redirectincludes\class-frontend.php:74
actionwc_ajax_get_wc_tb_refreshed_modalincludes\class-frontend.php:84
actionwc_ajax_set_wc_tb_loan_duration_sessionincludes\class-frontend.php:85
actioninitincludes\class-plugin.php:28
filterwoocommerce_payment_gatewaysincludes\class-plugin.php:42
filterwoocommerce_thankyou_order_received_textincludes\class-plugin.php:47
filterwoocommerce_new_order_note_dataincludes\class-plugin.php:186
actionadmin_initincludes\class-plugin.php:221
actionadmin_noticesincludes\class-requirements.php:23
actionplugins_loadedna-splatky-tb.php:24
Maintenance & Trust

Na splátkyTB Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 19, 2022
PHP min version7.0
Downloads847

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Na splátkyTB Developer Profile

Webikon s.r.o.

2 plugins · 700 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Na splátkyTB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/na-splatky-tb/dist/css/main.css/wp-content/plugins/na-splatky-tb/dist/js/main.js
Script Paths
/wp-content/plugins/na-splatky-tb/dist/js/main.js
Version Parameters
na-splatky-tb/dist/css/main.css?ver=na-splatky-tb/dist/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
na-splatky-tb-btnna-splatky-tb-btn--checkoutjs-open-na-splatky-tb-modalna-splatky-tb-btn--productna-splatky-tb-btn-wrappernasplatky-logotext
Data Attributes
data-modalid="nasplatky"
JS Globals
wc_tb_nasplatky_params
REST Endpoints
/wp-json/na-splatky-tb
Shortcode Output
Compute <span class="nasplatky-logotext">Na splátky<sup>TB</sup></span>
FAQ

Frequently Asked Questions about Na splátkyTB