
Фулфилмент от Почты России для маркетплейса Dokan Security & Risk Analysis
wordpress.org/plugins/russian-post-for-dokan-marketplaceФулфилмент от Почты России для маркетплейса на базе Dokan.
Is Фулфилмент от Почты России для маркетплейса Dokan Safe to Use in 2026?
Generally Safe
Score 85/100Фулфилмент от Почты России для маркетплейса Dokan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "russian-post-for-dokan-marketplace" v1.0.4 plugin presents a concerning security posture due to its significant attack surface lacking proper authentication. All five identified AJAX handlers do not have authentication checks, meaning any user, including unauthenticated ones, could potentially trigger these actions. While the plugin demonstrates good practices by using prepared statements for all SQL queries and has a clean vulnerability history with no known CVEs, this is heavily overshadowed by the lack of security on its entry points. The taint analysis found four flows with unsanitized paths, although they were not flagged as critical or high severity. This suggests a potential for issues if data is not handled carefully within these flows, even if they don't directly lead to immediate exploits in this specific analysis. The overall impression is a plugin that has some good technical foundations but suffers from critical oversight in securing its interactive components, making it a target for attackers seeking to leverage unauthenticated actions.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Large attack surface without auth checks
Фулфилмент от Почты России для маркетплейса Dokan Security Vulnerabilities
Фулфилмент от Почты России для маркетплейса Dokan Release Timeline
Фулфилмент от Почты России для маркетплейса Dokan Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Фулфилмент от Почты России для маркетплейса Dokan Attack Surface
AJAX Handlers 5
WordPress Hooks 37
Scheduled Events 1
Maintenance & Trust
Фулфилмент от Почты России для маркетплейса Dokan Maintenance & Trust
Maintenance Signals
Community Trust
Фулфилмент от Почты России для маркетплейса Dokan Alternatives
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
MyParcel
woocommerce-myparcel
Export your WooCommerce orders to MyParcel (www.myparcel.nl) and print labels directly from the WooCommerce admin
YITH WooCommerce Order & Shipment Tracking
yith-woocommerce-order-tracking
Add an easy tool to manage order shipping information of your shop and to notified your customers about the shipping.
Frenet Shipping Gateway for WooCommerce – Correios, Etiquetas e Rastreio
woo-shipping-gateway
Frete inteligente, simples e acessível para negócios que querem crescer
Фулфилмент от Почты России для маркетплейса Dokan Developer Profile
7 plugins · 60 total installs
How We Detect Фулфилмент от Почты России для маркетплейса Dokan
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/russian-post-for-dokan-marketplace/assets/css/backend_style.css/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/backend_script.js/wp-content/plugins/russian-post-for-dokan-marketplace/assets/css/frontend_style.css/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/frontend_script.js/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/backend_script.js/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/frontend_script.jsrussian-post-for-dokan-marketplace/assets/css/backend_style.css?ver=russian-post-for-dokan-marketplace/assets/js/backend_script.js?ver=russian-post-for-dokan-marketplace/assets/css/frontend_style.css?ver=russian-post-for-dokan-marketplace/assets/js/frontend_script.js?ver=HTML / DOM Fingerprints
russian-post-cancel-request-buttondata-id="cancel-order-request"russian_post_params/wp-json/russian-post-for-dokan-marketplace/v1/get-price