Витрина товаров Glopart Security & Risk Analysis

wordpress.org/plugins/product-widget-glopart

Теперь вы можете активно зарабатывать на продаже топовых товаров из каталога партнерских программ Glopart. Перейти на сайт Glopart.ru

10 active installs v1.0.3 PHP 5.6+ WP 4.7.11+ Updated Sep 19, 2018
%d0%b2%d0%b8%d1%82%d1%80%d0%b8%d0%bd%d0%b0-%d0%bf%d0%b0%d1%80%d1%82%d0%bd%d0%b5%d1%80%d1%81%d0%ba%d0%b8%d1%85-%d1%82%d0%be%d0%b2%d0%b0%d1%80%d0%be%d0%b2-wordpress%d0%ba%d0%b0%d1%82%d0%b0%d0%bb%d0%be%d0%b3-%d1%86%d0%b8%d1%84%d1%80%d0%be%d0%b2%d1%8b%d1%85-%d1%82%d0%be%d0%b2%d0%b0%d1%80%d0%be%d0%b2-wordpress%d0%ba%d1%83%d1%80%d1%81%d1%8b-glopartglopart-%d0%ba%d0%b0%d0%ba-%d0%b7%d0%b0%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%b0%d1%82%d1%8cglopart-wp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Витрина товаров Glopart Safe to Use in 2026?

Generally Safe

Score 85/100

Витрина товаров Glopart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "product-widget-glopart" v1.0.3 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs, lack of dangerous functions, and exclusive use of prepared statements for SQL queries are strong indicators of good development practices. The plugin also appears to have a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events contributing to potential entry points. However, significant concerns arise from the static analysis of its code. A critical finding is that 100% of its output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, there is a single taint flow identified with an unsanitized path, which, while not flagged as critical or high severity in this analysis, still warrants careful attention as it represents a potential avenue for malicious input processing. The plugin also performs external HTTP requests, and while no specific vulnerabilities are detailed, this functionality can introduce risks if not handled securely.

The lack of any recorded vulnerability history is a positive sign, suggesting the plugin has not been a frequent target or source of security issues. However, this can also be misleading if the plugin has not been subjected to thorough security audits or if the current lack of escape for output has simply gone unnoticed. The overall security profile is therefore a balance between a seemingly clean history and coding practices that introduce immediate, albeit potentially unexploited, risks, particularly concerning output escaping. Users should be aware of the XSS risks and the potential implications of the unsanitized taint flow.

Key Concerns

  • 100% of outputs are not properly escaped
  • Taint flow with unsanitized path
  • External HTTP requests without context
Vulnerabilities
None known

Витрина товаров Glopart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Витрина товаров Glopart Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
63
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped63 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<product-widget-glopart> (product-widget-glopart.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Витрина товаров Glopart Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsproduct-widget-glopart.php:21
actionwidgets_initproduct-widget-glopart.php:23
Maintenance & Trust

Витрина товаров Glopart Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 19, 2018
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Alternatives

Витрина товаров Glopart Alternatives

No alternatives data available yet.

Developer Profile

Витрина товаров Glopart Developer Profile

Ivan

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Витрина товаров Glopart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-widget-glopart/assets/css/style.css
Version Parameters
product-widget-glopart/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
example
Data Attributes
id="pwg_glopart"for="pwg_glopart-title"name="pwg_glopart-title"id="pwg_glopart-glopart_id"name="pwg_glopart-glopart_id"id="pwg_glopart-glopart_count"+7 more
FAQ

Frequently Asked Questions about Витрина товаров Glopart