Nip Finder Security & Risk Analysis

wordpress.org/plugins/nip-finder

Automatyczne dane firmowe z GUS do WooCommerce. Szybsze zamówienia B2B, zero błędów w fakturach!

20 active installs v1.3.6 PHP 7.4+ WP 6.2+ Updated Nov 20, 2025
b2bfakturagusnipwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nip Finder Safe to Use in 2026?

Generally Safe

Score 100/100

Nip Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "nip-finder" plugin v1.3.6 presents a significant security concern due to its handling of AJAX requests. While the plugin demonstrates good practices in other areas, such as the absence of dangerous functions, the use of prepared statements for all SQL queries, and a high rate of output escaping, the fact that all 7 of its AJAX handlers lack authentication checks creates a substantial attack surface.

This means that any unauthenticated user can trigger these AJAX actions, potentially leading to unauthorized data access, modification, or other malicious activities depending on the functionality of these endpoints. The absence of any recorded historical vulnerabilities is a positive sign, suggesting a generally well-maintained codebase. However, the current state of unprotected AJAX handlers overshadows this strength and represents a critical vulnerability that should be addressed immediately to secure the plugin's overall posture.

Key Concerns

  • 7 AJAX handlers without authentication checks
Vulnerabilities
None known

Nip Finder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nip Finder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
18 escaped
Nonce Checks
9
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

95% escaped19 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
nip_finder_maybe_update_token (admin\class-nip-finder-admin.php:229)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Nip Finder Attack Surface

Entry Points7
Unprotected7

AJAX Handlers 7

authwp_ajax_nip_finder_check_statusincludes\class-nip-finder.php:141
authwp_ajax_nip_finder_registerincludes\class-nip-finder.php:142
authwp_ajax_nip_finder_register_subscriptionincludes\class-nip-finder.php:143
authwp_ajax_nip_finder_fetch_gus_dataincludes\class-nip-finder.php:162
noprivwp_ajax_nip_finder_fetch_gus_dataincludes\class-nip-finder.php:163
authwp_ajax_nip_finder_fetch_citiesincludes\class-nip-finder.php:167
noprivwp_ajax_nip_finder_fetch_citiesincludes\class-nip-finder.php:168
WordPress Hooks 15
actionadmin_enqueue_scriptsincludes\class-nip-finder.php:133
actionadmin_enqueue_scriptsincludes\class-nip-finder.php:134
actionwoocommerce_settings_tabs_arrayincludes\class-nip-finder.php:135
actionwoocommerce_settings_tabs_nip_finderincludes\class-nip-finder.php:136
actionwoocommerce_update_options_nip_finderincludes\class-nip-finder.php:137
actionwoocommerce_settings_save_nip_finderincludes\class-nip-finder.php:138
actionadmin_initincludes\class-nip-finder.php:139
actionwp_enqueue_scriptsincludes\class-nip-finder.php:157
actionwp_enqueue_scriptsincludes\class-nip-finder.php:158
actionwp_enqueue_scriptsincludes\class-nip-finder.php:159
actionwp_enqueue_scriptsincludes\class-nip-finder.php:160
actionwoocommerce_checkout_update_order_metaincludes\class-nip-finder.php:164
actionwoocommerce_admin_order_data_after_billing_addressincludes\class-nip-finder.php:165
actionwoocommerce_checkout_processincludes\class-nip-finder.php:166
filterwoocommerce_checkout_fieldsincludes\class-nip-finder.php:170
Maintenance & Trust

Nip Finder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 20, 2025
PHP min version7.4
Downloads503

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Nip Finder Developer Profile

codepress

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nip Finder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nip-finder/css/nip-finder-admin.css/wp-content/plugins/nip-finder/js/nip-finder-admin.js
Script Paths
/wp-content/plugins/nip-finder/js/nip-finder-admin.js
Version Parameters
nip-finder/css/nip-finder-admin.css?ver=nip-finder/js/nip-finder-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nip_finder_input
JS Globals
nip_finder
FAQ

Frequently Asked Questions about Nip Finder