
Robokassa Shortcode Security & Risk Analysis
wordpress.org/plugins/robokassa-shortcodeThis plugin allows you to place a payment button in any Robokassa your post or on any page.
Is Robokassa Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Robokassa Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The robokassa-shortcode plugin v1.4.1 demonstrates a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and its SQL queries are all properly prepared, indicating good practices in data sanitization for database interactions. The plugin also has a very small attack surface, with only one shortcode and no AJAX handlers, REST API routes, or cron events. Furthermore, taint analysis shows no identified flows with unsanitized paths, which is a strong indicator against critical injection vulnerabilities.
However, significant concerns exist regarding output escaping and the use of dangerous functions. A low percentage (29%) of outputs are properly escaped, leaving the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The presence of the `create_function` function is a known security risk, as it can lead to code injection if used with unsanitized input. The absence of nonce checks and capability checks on its single entry point (the shortcode) means that any authenticated user could potentially trigger the shortcode's functionality, regardless of their intended permissions.
Given the lack of historical vulnerabilities, it's possible these weaknesses haven't been exploited or discovered yet. However, the combination of unescaped output and the use of `create_function` represents a tangible risk. While the overall attack surface is small, these specific code signals warrant attention to prevent potential security breaches.
Key Concerns
- Low percentage of properly escaped output
- Use of dangerous function 'create_function'
- Missing nonce checks on entry points
- Missing capability checks on entry points
Robokassa Shortcode Security Vulnerabilities
Robokassa Shortcode Code Analysis
Dangerous Functions Found
Output Escaping
Robokassa Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Robokassa Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Robokassa Shortcode Alternatives
Robokassa for WooCommerce
robokassa-for-woocommerce
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
Robokassa Payment Gateway (Saphali)
robokassa-payment-gateway-saphali
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
Robokassa for Jigoshop
robokassa-for-jigoshop
Allows you to use Robokassa payment gateway with the Jigoshop ecommerce plugin.
Robokassa payment gateway for Woocommerce
robokassa
Позволяет использовать интерфейс (платежный шлюз) для оплаты через Робокассу в WooCommerce. Поддерживает интеграцию чеков (закон 54-ФЗ)
Robokassa payment gateway with Subscriptions support
robokassa-subscriptions
Robokassa сделала свой популярный модуль для WooCommerce еще лучше - теперь он поддерживает не только обычные продажи, но и функционал подписок, а так …
Robokassa Shortcode Developer Profile
1 plugin · 30 total installs
How We Detect Robokassa Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/robokassa-shortcode/styles.css/wp-content/plugins/robokassa-shortcode/img/icon.pngrobokassa-shortcode/styles.css?ver=HTML / DOM Fingerprints
rksksendrcskcancelid="insert_rksc"<a id="rkbutton onclick='if(document.getElementById("rkwarp").style.display=="block"){document.getElementById("rkwarp").style.display="none"}else{document.getElementById("rkwarp