
Woo NovaPoshta. Электронная накладная Security & Risk Analysis
wordpress.org/plugins/nova-poshta-declarationsНовая почта электронные накладные. Вывод электронных накладных в заказе (woocommerce).
Is Woo NovaPoshta. Электронная накладная Safe to Use in 2026?
Generally Safe
Score 85/100Woo NovaPoshta. Электронная накладная has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nova-poshta-declarations" v0.16 plugin exhibits a generally strong security posture, with no recorded vulnerabilities and positive indicators in the static analysis. The code demonstrates a commitment to secure practices by exclusively using prepared statements for SQL queries and implementing nonce checks and capability checks, indicating an effort to prevent common web attacks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests reduces the potential for critical security flaws. The lack of taint analysis findings suggests that data flow issues, which can lead to vulnerabilities like command injection or path traversal, are not present in the analyzed code. However, a notable concern is the 31% of outputs that are not properly escaped. While not directly flagged as a vulnerability in this analysis, unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is displayed without sanitization. The plugin's static analysis shows a single entry point via a shortcode, and critically, all entry points appear to be protected by authentication or permission checks, which is a significant strength. In conclusion, the plugin is well-defended against many common attack vectors. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks.
Key Concerns
- Unescaped output detected (31%)
Woo NovaPoshta. Электронная накладная Security Vulnerabilities
Woo NovaPoshta. Электронная накладная Code Analysis
Output Escaping
Data Flow Analysis
Woo NovaPoshta. Электронная накладная Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Woo NovaPoshta. Электронная накладная Maintenance & Trust
Maintenance Signals
Community Trust
Woo NovaPoshta. Электронная накладная Alternatives
Shipping for Nova Poshta
nova-poshta-ttn
Доставка на відділення, поштомат та адресу (з автопошуком вулиць). Створення ТТН. Найзручніший плагін.
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce
wc-ukr-shipping
Connect Nova Poshta, Ukrposhta, Meest or international delivery services with your store. Create labels, track orders and calculate rates in one place …
Morkva UA Shipping
morkva-ua-shipping
Нова Пошта по Україні та закордон, Укрпошта по Україні та закордон. Rozetka Delivery. Зручне створення ТТН. Друк ТТН. Сумісний з іншими плагінами.
Shipping of Nova Poshta for WooCommerce
wc-nova-poshta-for-shop
Підключення служби доставки Нова Пошта до Вашого сайту (WooCommerce)
Woo NovaPoshta. Электронная накладная Developer Profile
1 plugin · 10 total installs
How We Detect Woo NovaPoshta. Электронная накладная
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nova-poshta-declarations/assets/tracking.css/wp-content/plugins/nova-poshta-declarations/assets/track.min.js/wp-content/plugins/nova-poshta-declarations/assets/track.min.js/wp-content/plugins/nova-poshta-declarations/assets/tracking.css?ver=1.0/wp-content/plugins/nova-poshta-declarations/assets/track.min.js?ver=1.0HTML / DOM Fingerprints
np_forudpdatenp-user-inputnpen_wrappernp_forudpdatenp-user-inputnp-trackingnp-w-br-0np-first-state+19 moredata-ajax<th scope="row"><span class="np_forudpdate">Номер ЭН</span></th>