
Онлайн касса – nanokassa.ru Security & Risk Analysis
wordpress.org/plugins/nanokassaПлагин для фискализации чеков согласно 54 ФЗ и облачной онлайн кассы Nanokassa.ru
Is Онлайн касса – nanokassa.ru Safe to Use in 2026?
Generally Safe
Score 100/100Онлайн касса – nanokassa.ru has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Nanokassa v1.0.2 plugin exhibits a generally positive security posture, with no known vulnerabilities (CVEs) or critical taint analysis findings. The absence of known vulnerabilities and the low number of code signals like dangerous functions and external HTTP requests are encouraging. The high percentage of properly escaped output (84%) also suggests good development practices for preventing cross-site scripting (XSS) vulnerabilities.
However, there are areas for improvement. The complete lack of nonce checks on AJAX handlers is a significant concern, potentially exposing the plugin to cross-site request forgery (CSRF) attacks if any AJAX functionality exists but is not explicitly detailed in the attack surface. Furthermore, the statistic indicating 100% of SQL queries are not using prepared statements is a critical security flaw. This widespread use of raw SQL queries without proper sanitization or parameterization opens the door to SQL injection vulnerabilities, allowing attackers to manipulate database queries and potentially access or modify sensitive data.
While the vulnerability history is clean, this can be due to the plugin's age or a lack of historical analysis. The current code analysis reveals a critical weakness in SQL query handling and a potential weakness in AJAX security due to missing nonce checks. The presence of file operations and external HTTP requests, while not inherently insecure, warrants attention to ensure they are handled safely and do not introduce further attack vectors. The plugin demonstrates a commitment to output sanitization but needs to address fundamental security practices related to database interactions and authentication mechanisms.
Key Concerns
- All SQL queries are not using prepared statements
- No nonce checks on AJAX handlers
- Some output is not properly escaped
- File operations present
- External HTTP requests present
Онлайн касса – nanokassa.ru Security Vulnerabilities
Онлайн касса – nanokassa.ru Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Онлайн касса – nanokassa.ru Attack Surface
WordPress Hooks 9
Maintenance & Trust
Онлайн касса – nanokassa.ru Maintenance & Trust
Maintenance Signals
Community Trust
Онлайн касса – nanokassa.ru Alternatives
Фискализация чеков е-ОФД
eofdsupport
Плагин для WooCommerce, для фискализации чеков согласно 54 ФЗ, арендованной облачной онлайн кассы оператора фискальных данных е-ОФД.
ЮKassa для WooCommerce
yookassa
Прием платежей на сайтах WooCommerce. Разработка и поддержка — компания ЮMoney
Robokassa payment gateway for Woocommerce
robokassa
Позволяет использовать интерфейс (платежный шлюз) для оплаты через Робокассу в WooCommerce. Поддерживает интеграцию чеков (закон 54-ФЗ)
Rabo Smart Pay for WooCommerce
woo-rabo-omnikassa
One of the best integrated and easy to use Payment Method plug-in for Rabo Smart Pay in WooCommerce.
Payment gateway – Robokassa for WooCommerce
wc-robokassa
Integration Robokassa in WooCommerce as payment gateway plugin.
Онлайн касса – nanokassa.ru Developer Profile
1 plugin · 0 total installs
How We Detect Онлайн касса – nanokassa.ru
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nanokassa/nanosys/css/nanokassa.css/wp-content/plugins/nanokassa/nanosys/js/nanokassa.js/wp-content/plugins/nanokassa/nanosys/views/nanokassa_view.js/wp-content/plugins/nanokassa/nanosys/js/nanokassa.js/wp-content/plugins/nanokassa/nanosys/views/nanokassa_view.jsnanokassa/nanosys/css/nanokassa.css?ver=nanokassa/nanosys/js/nanokassa.js?ver=nanokassa/nanosys/views/nanokassa_view.js?ver=HTML / DOM Fingerprints
nanokassa-settings-sectionnanokassa-input-groupnanokassa-labelnanokassa-select-wrapperdata-nanokassa-kassaiddata-nanokassa-kassatokendata-nanokassa-rezhim-nalognanokassa_paramsnanokassa_view