Онлайн касса – nanokassa.ru Security & Risk Analysis

wordpress.org/plugins/nanokassa

Плагин для фискализации чеков согласно 54 ФЗ и облачной онлайн кассы Nanokassa.ru

0 active installs v1.0.2 PHP + WP 4.8+ Updated Unknown
54-%d1%84%d0%b754fz%d0%be%d0%bd%d0%bb%d0%b0%d0%b9%d0%bd-%d0%ba%d0%b0%d1%81%d1%81%d0%b0kassaonline-kassa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Онлайн касса – nanokassa.ru Safe to Use in 2026?

Generally Safe

Score 100/100

Онлайн касса – nanokassa.ru has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The Nanokassa v1.0.2 plugin exhibits a generally positive security posture, with no known vulnerabilities (CVEs) or critical taint analysis findings. The absence of known vulnerabilities and the low number of code signals like dangerous functions and external HTTP requests are encouraging. The high percentage of properly escaped output (84%) also suggests good development practices for preventing cross-site scripting (XSS) vulnerabilities.

However, there are areas for improvement. The complete lack of nonce checks on AJAX handlers is a significant concern, potentially exposing the plugin to cross-site request forgery (CSRF) attacks if any AJAX functionality exists but is not explicitly detailed in the attack surface. Furthermore, the statistic indicating 100% of SQL queries are not using prepared statements is a critical security flaw. This widespread use of raw SQL queries without proper sanitization or parameterization opens the door to SQL injection vulnerabilities, allowing attackers to manipulate database queries and potentially access or modify sensitive data.

While the vulnerability history is clean, this can be due to the plugin's age or a lack of historical analysis. The current code analysis reveals a critical weakness in SQL query handling and a potential weakness in AJAX security due to missing nonce checks. The presence of file operations and external HTTP requests, while not inherently insecure, warrants attention to ensure they are handled safely and do not introduce further attack vectors. The plugin demonstrates a commitment to output sanitization but needs to address fundamental security practices related to database interactions and authentication mechanisms.

Key Concerns

  • All SQL queries are not using prepared statements
  • No nonce checks on AJAX handlers
  • Some output is not properly escaped
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Онлайн касса – nanokassa.ru Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Онлайн касса – nanokassa.ru Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
0 prepared
Unescaped Output
11
59 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared9 total queries

Output Escaping

84% escaped70 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save (nanosys\class-nanokassa-admin-settings.php:52)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Онлайн касса – nanokassa.ru Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwoocommerce_order_status_changednanokassa.php:56
actionwpsc_purchase_log_savenanokassa.php:57
actionnanokassa_settings_generalnanokassa.php:62
actionnanokassa_settings_woocommercenanokassa.php:63
actionnanokassa_settings_wpecnanokassa.php:64
actioninitnanokassa.php:74
actionadmin_headnanosys\class-nanokassa-admin.php:6
actionadmin_menunanosys\class-nanokassa-admin.php:7
actionadmin_menunanosys\class-nanokassa-admin.php:8
Maintenance & Trust

Онлайн касса – nanokassa.ru Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Онлайн касса – nanokassa.ru Developer Profile

nanokassa

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Онлайн касса – nanokassa.ru

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nanokassa/nanosys/css/nanokassa.css/wp-content/plugins/nanokassa/nanosys/js/nanokassa.js/wp-content/plugins/nanokassa/nanosys/views/nanokassa_view.js
Script Paths
/wp-content/plugins/nanokassa/nanosys/js/nanokassa.js/wp-content/plugins/nanokassa/nanosys/views/nanokassa_view.js
Version Parameters
nanokassa/nanosys/css/nanokassa.css?ver=nanokassa/nanosys/js/nanokassa.js?ver=nanokassa/nanosys/views/nanokassa_view.js?ver=

HTML / DOM Fingerprints

CSS Classes
nanokassa-settings-sectionnanokassa-input-groupnanokassa-labelnanokassa-select-wrapper
Data Attributes
data-nanokassa-kassaiddata-nanokassa-kassatokendata-nanokassa-rezhim-nalog
JS Globals
nanokassa_paramsnanokassa_view
FAQ

Frequently Asked Questions about Онлайн касса – nanokassa.ru