Prihlasovanie na sväté omše Security & Risk Analysis

wordpress.org/plugins/prihlasovanie-na-svate-omse

Prihlasovanie na sväté omše

0 active installs v1.9.1 PHP 5.2.4+ WP 3.5+ Updated Dec 22, 2021
kostolprihlasovaniesvate-omse
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Prihlasovanie na sväté omše Safe to Use in 2026?

Generally Safe

Score 85/100

Prihlasovanie na sväté omše has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "prihlasovanie-na-svate-omse" v1.9.1 plugin presents a significant security risk due to a large number of unprotected AJAX handlers and a complete lack of nonce and capability checks. While the static analysis indicates no dangerous functions or direct external HTTP requests, the 13 AJAX handlers without authentication checks create a substantial attack surface. The taint analysis revealing 9 flows with unsanitized paths, all of critical severity, directly points to potential vulnerabilities where user input could be misused to manipulate the application, likely leading to unauthorized actions or data exposure. The plugin's vulnerability history is clean, which might suggest a lack of previous scrutiny or a low profile. However, the current code analysis reveals fundamental security oversights that, if exploited, could be severe. The extensive use of raw SQL queries without prepared statements further exacerbates the risk, making it susceptible to SQL injection attacks. The moderate rate of properly escaped output is a slight positive, but does not mitigate the critical issues found in the taint analysis and unprotected entry points.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
  • Raw SQL without prepared statements
  • Missing nonce checks on AJAX
  • Missing capability checks
Vulnerabilities
None known

Prihlasovanie na sväté omše Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Prihlasovanie na sväté omše Release Timeline

v1.9.1Current
v1.9
v1.8
v1.7
v1.6
v1.5
v1.3
v1.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Prihlasovanie na sväté omše Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
0 prepared
Unescaped Output
48
109 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared19 total queries

Output Escaping

69% escaped157 total outputs
Data Flows · Security
9 unsanitized

Data Flow Analysis

9 flows9 with unsanitized paths
tsspsv_registration_history_table_callback (admin/registration_history_table.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
13 unprotected

Prihlasovanie na sväté omše Attack Surface

Entry Points17
Unprotected13

AJAX Handlers 13

authwp_ajax_tsspsv_registration_tableadmin/admin.php:13
authwp_ajax_tsspsv_registration_history_tableadmin/admin.php:14
authwp_ajax_tsspsv_services_tableadmin/admin.php:15
authwp_ajax_tsspsv_delete_record_adminadmin/admin.php:16
authwp_ajax_tsspsv_save_service_editadmin/admin.php:17
authwp_ajax_tsspsv_add_service_saveadmin/admin.php:18
authwp_ajax_tsspsv_new_service_rowadmin/admin.php:19
authwp_ajax_tsspsv_reorder_servicesadmin/admin.php:20
authwp_ajax_tsspsv_csv_exportadmin/admin.php:21
authwp_ajax_tsspsv_submit_formincludes/functions.php:8
noprivwp_ajax_tsspsv_submit_formincludes/functions.php:9
authwp_ajax_tsspsv_submit_dereg_formincludes/functions.php:10
noprivwp_ajax_tsspsv_submit_dereg_formincludes/functions.php:11

Shortcodes 4

[tsspsv_form] includes/shortcode.php:7
[tsspsv_dereg_form] includes/shortcode.php:8
[tsspsv_service] includes/shortcode.php:9
[tsspsv_day_of_service] includes/shortcode.php:10
WordPress Hooks 13
actioninitadmin/admin.php:8
actionadmin_initadmin/admin.php:9
actionadmin_enqueue_scriptsadmin/admin.php:10
actionadmin_enqueue_scriptsadmin/admin.php:11
actionadmin_menuadmin/admin.php:28
actionupdate_option_tsspsv_optionsadmin/settings.php:163
actiontsspsv_reset_formsadmin/settings.php:209
actionplugin_loadedincludes/db.php:67
actioninitincludes/shortcode.php:12
actioninitprihlasovanie-na-svate-omse.php:95
actionwp_enqueue_scriptsprihlasovanie-na-svate-omse.php:103
actionwp_enqueue_scriptsprihlasovanie-na-svate-omse.php:124
filtercron_schedulesprihlasovanie-na-svate-omse.php:135

Scheduled Events 3

tsspsv_reset_forms
tsspsv_reset_forms
tsspsv_reset_forms
Maintenance & Trust

Prihlasovanie na sväté omše Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 22, 2021
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Prihlasovanie na sväté omše Alternatives

No alternatives data available yet.

Developer Profile

Prihlasovanie na sväté omše Developer Profile

Matej Podstrelenec

6 plugins · 540 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Prihlasovanie na sväté omše

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prihlasovanie-na-svate-omse/css/spirit-registration.css/wp-content/plugins/prihlasovanie-na-svate-omse/js/spirit-registration.js/wp-content/plugins/prihlasovanie-na-svate-omse/css/spirit-registration-admin.css/wp-content/plugins/prihlasovanie-na-svate-omse/js/spirit-registration-admin.js
Script Paths
/wp-content/plugins/prihlasovanie-na-svate-omse/js/spirit-registration.js/wp-content/plugins/prihlasovanie-na-svate-omse/js/spirit-registration-admin.js
Version Parameters
prihlasovanie-na-svate-omse/css/spirit-registration.css?ver=prihlasovanie-na-svate-omse/js/spirit-registration.js?ver=prihlasovanie-na-svate-omse/css/spirit-registration-admin.css?ver=prihlasovanie-na-svate-omse/js/spirit-registration-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
spirit-registration-admin-css
HTML Comments
<!-- Everything related to Wordpress administration. --><!-- Initiate admin menu --><!-- Enqueue admin styles --><!-- Enqueue admin scripts -->+2 more
Data Attributes
data-service-id
JS Globals
my_ajax_object
REST Endpoints
/wp-json/spirit-registration
Shortcode Output
[spirit_registration_form]
FAQ

Frequently Asked Questions about Prihlasovanie na sväté omše