Naver webmaster syndication v2 Security & Risk Analysis

wordpress.org/plugins/naver-webmaster-tool-syndication-v2

네이버 웹마스터도구 및 신디케이션 v2 연동 플러그인입니다.

500 active installs v1.1 PHP + WP 3.7.1+ Updated Nov 28, 2017
naversearchengineseosyndicationweb
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Naver webmaster syndication v2 Safe to Use in 2026?

Generally Safe

Score 85/100

Naver webmaster syndication v2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'naver-webmaster-tool-syndication-v2' v1.1 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs and a clean vulnerability history are strong indicators of a well-maintained codebase. The plugin also demonstrates good practices by avoiding dangerous functions and file operations. However, significant concerns arise from the static analysis. The complete lack of nonce checks and capability checks, coupled with 0% of AJAX handlers and REST API routes having authentication checks, creates a substantial attack surface that is entirely unprotected. This is a critical oversight that could allow unauthorized users to trigger plugin functionalities. Furthermore, a concerning 11% of output is not properly escaped, which, while not immediately critical given the other findings, opens the door to potential cross-site scripting (XSS) vulnerabilities if any of the entry points were exploitable. The taint analysis, while showing no critical or high severity flows, did identify 3 flows with unsanitized paths, which warrants attention in conjunction with the lack of input validation. The SQL query analysis also shows room for improvement, with 50% of queries not using prepared statements. This increases the risk of SQL injection vulnerabilities, especially if the plugin handles user-provided data. In conclusion, while the plugin has a clean past and avoids certain dangerous practices, the current version has critical security weaknesses in its lack of input validation and authentication, making it a potential target. The static analysis highlights the most pressing issues that need immediate remediation.

Key Concerns

  • No capability checks
  • No nonce checks
  • Unescaped output (11%)
  • SQL queries not using prepared statements (50%)
  • Flows with unsanitized paths (3)
  • Unprotected AJAX handlers (0/0)
  • Unprotected REST API routes (0/0)
Vulnerabilities
None known

Naver webmaster syndication v2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Naver webmaster syndication v2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
3 prepared
Unescaped Output
57
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

50% prepared6 total queries

Output Escaping

11% escaped64 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
table_bar (class\nws_tpl_class.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Naver webmaster syndication v2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitclass\nws_class.php:109
actionadmin_initclass\nws_class.php:266
actionadmin_menuclass\nws_class.php:267
actiontrashed_postclass\nws_class.php:270
actionpublish_postclass\nws_class.php:271
filterexcerpt_moreinclude\api.php:22
Maintenance & Trust

Naver webmaster syndication v2 Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.0
Last updatedNov 28, 2017
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Naver webmaster syndication v2 Developer Profile

iamgood

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Naver webmaster syndication v2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/naver-webmaster-tool-syndication-v2/css/admin.css/wp-content/plugins/naver-webmaster-tool-syndication-v2/js/common.js
Script Paths
/wp-content/plugins/naver-webmaster-tool-syndication-v2/js/common.js
Version Parameters
naver-webmaster-tool-syndication-v2/css/admin.css?ver=naver-webmaster-tool-syndication-v2/js/common.js?ver=

HTML / DOM Fingerprints

CSS Classes
buttonbutton-primarytablenavtablenav-pages
Data Attributes
onchange
JS Globals
$_nwsv2
FAQ

Frequently Asked Questions about Naver webmaster syndication v2