Woo NovaPoshta. Электронная накладная Security & Risk Analysis

wordpress.org/plugins/nova-poshta-declarations

Новая почта электронные накладные. Вывод электронных накладных в заказе (woocommerce).

10 active installs v0.16 PHP + WP 4.4+ Updated Feb 4, 2017
%d0%bd%d0%be%d0%b2%d0%b0-%d0%bf%d0%be%d1%88%d1%82%d0%b0%d0%b2%d0%b8%d0%b4%d0%b6%d0%b5%d1%82-%d0%bd%d0%be%d0%b2%d0%be%d0%b9-%d0%bf%d0%be%d1%87%d1%82%d1%8b%d0%bd%d0%be%d0%b2%d0%b0%d1%8f-%d0%bf%d0%be%d1%87%d1%82%d0%b0%d1%8d%d0%bb%d0%b5%d0%ba%d1%82%d1%80%d0%be%d0%bd%d0%bd%d1%8b%d0%b5-%d0%bd%d0%b0%d0%ba%d0%bb%d0%b0%d0%b4%d0%bd%d1%8b%d0%b5woocommerce-%d0%bd%d0%be%d0%b2%d0%b0%d1%8f-%d0%bf%d0%be%d1%87%d1%82%d0%b0
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Woo NovaPoshta. Электронная накладная Safe to Use in 2026?

Generally Safe

Score 85/100

Woo NovaPoshta. Электронная накладная has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "nova-poshta-declarations" v0.16 plugin exhibits a generally strong security posture, with no recorded vulnerabilities and positive indicators in the static analysis. The code demonstrates a commitment to secure practices by exclusively using prepared statements for SQL queries and implementing nonce checks and capability checks, indicating an effort to prevent common web attacks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests reduces the potential for critical security flaws. The lack of taint analysis findings suggests that data flow issues, which can lead to vulnerabilities like command injection or path traversal, are not present in the analyzed code. However, a notable concern is the 31% of outputs that are not properly escaped. While not directly flagged as a vulnerability in this analysis, unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is displayed without sanitization. The plugin's static analysis shows a single entry point via a shortcode, and critically, all entry points appear to be protected by authentication or permission checks, which is a significant strength. In conclusion, the plugin is well-defended against many common attack vectors. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks.

Key Concerns

  • Unescaped output detected (31%)
Vulnerabilities
None known

Woo NovaPoshta. Электронная накладная Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Woo NovaPoshta. Электронная накладная Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
9 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
npen_admin_settings (NpControllerClass.php:135)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Woo NovaPoshta. Электронная накладная Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[getnp_number] NpControllerClass.php:24
WordPress Hooks 9
actionadmin_enqueue_scriptsnova-poshta-declarations.php:24
filterplugin_row_metanova-poshta-declarations.php:36
actioninitNpControllerClass.php:14
actionwoocommerce_initNpControllerClass.php:17
actionplugins_loadedNpControllerClass.php:20
actionadmin_menuNpControllerClass.php:21
actionwoocommerce_order_items_tableNpControllerClass.php:26
actionadd_meta_boxesNpControllerClass.php:118
actionsave_postwc_np_metbox.php:7
Maintenance & Trust

Woo NovaPoshta. Электронная накладная Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 4, 2017
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Woo NovaPoshta. Электронная накладная Developer Profile

iytin

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo NovaPoshta. Электронная накладная

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nova-poshta-declarations/assets/tracking.css/wp-content/plugins/nova-poshta-declarations/assets/track.min.js
Script Paths
/wp-content/plugins/nova-poshta-declarations/assets/track.min.js
Version Parameters
/wp-content/plugins/nova-poshta-declarations/assets/tracking.css?ver=1.0/wp-content/plugins/nova-poshta-declarations/assets/track.min.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
np_forudpdatenp-user-inputnpen_wrappernp_forudpdatenp-user-inputnp-trackingnp-w-br-0np-first-state+19 more
Data Attributes
data-ajax
Shortcode Output
<th scope="row"><span class="np_forudpdate">Номер ЭН</span></th>
FAQ

Frequently Asked Questions about Woo NovaPoshta. Электронная накладная