Ninja Araçlar Security & Risk Analysis

wordpress.org/plugins/ninja-araclar

Ninja Araçlar eklentisi, genel anlamda temalarına Süperlig, Burçlar, Döviz ve Hava Durumu eklemek isteyenler için geliştirilmiştir.

40 active installs v1.0.1 PHP + WP 4.4.1+ Updated Unknown
burclardovizdoviz-kurlarisuper-ligsuper-lig-puan-durumu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ninja Araçlar Safe to Use in 2026?

Generally Safe

Score 100/100

Ninja Araçlar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "ninja-araclar" v1.0.1 demonstrates a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, or shortcodes, and no direct file operations or external HTTP requests. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stability. However, significant concerns are present regarding input sanitization and authentication. The complete absence of nonce checks and capability checks is a critical oversight, especially given the presence of cron events which could potentially be triggered in unintended ways. While the plugin uses prepared statements for a majority of its SQL queries, the remaining percentage, along with the 41 output operations where 59% are properly escaped, indicates potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled meticulously elsewhere. The bundled Guzzle library also presents a potential risk if it's outdated and contains known vulnerabilities.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • SQL queries not using prepared statements
  • Output not properly escaped
  • Bundled library (Guzzle) potential risk
Vulnerabilities
None known

Ninja Araçlar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ninja Araçlar Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
10 prepared
Unescaped Output
17
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

56% prepared18 total queries

Output Escaping

59% escaped41 total outputs
Attack Surface

Ninja Araçlar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-ninja-araclar.php:178
actionadmin_enqueue_scriptsincludes\class-ninja-araclar.php:193
actionadmin_enqueue_scriptsincludes\class-ninja-araclar.php:194
actionpuantablosu_cronincludes\class-ninja-araclar.php:195
actionburclar_cronincludes\class-ninja-araclar.php:196
actiondoviz_cronincludes\class-ninja-araclar.php:197
actionwp_enqueue_scriptsincludes\class-ninja-araclar.php:214
actionwp_enqueue_scriptsincludes\class-ninja-araclar.php:215
actionwidgets_initincludes\class-ninja-araclar.php:216

Scheduled Events 3

puantablosu_cron
burclar_cron
doviz_cron
Maintenance & Trust

Ninja Araçlar Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads12K

Community Trust

Rating70/100
Number of ratings4
Active installs40
Developer Profile

Ninja Araçlar Developer Profile

TemaMarket

2 plugins · 50 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ninja Araçlar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ninja-araclar/admin/css/ninja-araclar-admin.css/wp-content/plugins/ninja-araclar/admin/js/ninja-araclar-admin.js
Script Paths
/wp-content/plugins/ninja-araclar/admin/js/ninja-araclar-admin.js
Version Parameters
ninja-araclar-admin.css?ver=ninja-araclar-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ninja Araçlar