Фулфилмент от Почты России для маркетплейса Dokan Security & Risk Analysis

wordpress.org/plugins/russian-post-for-dokan-marketplace

Фулфилмент от Почты России для маркетплейса на базе Dokan.

0 active installs v1.0.4 PHP 7.4+ WP 5.5+ Updated Dec 14, 2022
deliverydokanmarketplaceshippingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Фулфилмент от Почты России для маркетплейса Dokan Safe to Use in 2026?

Generally Safe

Score 85/100

Фулфилмент от Почты России для маркетплейса Dokan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "russian-post-for-dokan-marketplace" v1.0.4 plugin presents a concerning security posture due to its significant attack surface lacking proper authentication. All five identified AJAX handlers do not have authentication checks, meaning any user, including unauthenticated ones, could potentially trigger these actions. While the plugin demonstrates good practices by using prepared statements for all SQL queries and has a clean vulnerability history with no known CVEs, this is heavily overshadowed by the lack of security on its entry points. The taint analysis found four flows with unsanitized paths, although they were not flagged as critical or high severity. This suggests a potential for issues if data is not handled carefully within these flows, even if they don't directly lead to immediate exploits in this specific analysis. The overall impression is a plugin that has some good technical foundations but suffers from critical oversight in securing its interactive components, making it a target for attackers seeking to leverage unauthenticated actions.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • Large attack surface without auth checks
Vulnerabilities
None known

Фулфилмент от Почты России для маркетплейса Dokan Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Фулфилмент от Почты России для маркетплейса Dokan Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

Фулфилмент от Почты России для маркетплейса Dokan Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
27
97 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

78% escaped124 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
add_vendor_pdf (russian-post-for-dokan-marketplace.php:321)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Фулфилмент от Почты России для маркетплейса Dokan Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_dokan_settingsincludes\dokan-custom-settings-tab.php:149
authwp_ajax_get_russian_post_pricerussian-post-for-dokan-marketplace.php:57
noprivwp_ajax_get_russian_post_pricerussian-post-for-dokan-marketplace.php:58
authwp_ajax_send_cancel_requestrussian-post-for-dokan-marketplace.php:85
noprivwp_ajax_send_cancel_requestrussian-post-for-dokan-marketplace.php:86
WordPress Hooks 37
actioncancel_order_send_emailemails\VendorCancelOrderRequest.php:30
filterdokan_get_dashboard_settings_navincludes\dokan-custom-settings-tab.php:25
filterdokan_dashboard_settings_heading_titleincludes\dokan-custom-settings-tab.php:43
filterdokan_dashboard_settings_helper_textincludes\dokan-custom-settings-tab.php:61
actiondokan_render_settings_contentincludes\dokan-custom-settings-tab.php:123
filterwoocommerce_email_attachmentsincludes\functions.php:44
filterwoocommerce_email_attachmentsincludes\functions.php:45
filterwoocommerce_email_enabled_new_orderincludes\functions.php:184
filterwoocommerce_email_recipient_new_orderincludes\functions.php:185
actionadmin_initrussian-post-for-dokan-marketplace.php:50
actionadmin_initrussian-post-for-dokan-marketplace.php:51
actionwp_enqueue_scriptsrussian-post-for-dokan-marketplace.php:52
actionwoocommerce_after_shipping_raterussian-post-for-dokan-marketplace.php:53
actionwoocommerce_checkout_create_order_shipping_itemrussian-post-for-dokan-marketplace.php:54
actionwoocommerce_shipping_packagesrussian-post-for-dokan-marketplace.php:55
actionwoocommerce_checkout_processrussian-post-for-dokan-marketplace.php:56
actionwoocommerce_after_checkout_billing_formrussian-post-for-dokan-marketplace.php:59
actionwoocommerce_shipping_initrussian-post-for-dokan-marketplace.php:61
filterwoocommerce_shipping_methodsrussian-post-for-dokan-marketplace.php:63
actionwoocommerce_payment_completerussian-post-for-dokan-marketplace.php:64
actionwoocommerce_order_status_processingrussian-post-for-dokan-marketplace.php:65
actionwoocommerce_after_order_itemmetarussian-post-for-dokan-marketplace.php:66
actionwoocommerce_after_order_itemmetarussian-post-for-dokan-marketplace.php:67
actionwoocommerce_admin_order_item_valuesrussian-post-for-dokan-marketplace.php:68
actionwoocommerce_after_checkout_billing_formrussian-post-for-dokan-marketplace.php:70
actionwoocommerce_review_order_before_shippingrussian-post-for-dokan-marketplace.php:71
actionwoocommerce_cart_totals_before_shippingrussian-post-for-dokan-marketplace.php:72
actionwoocommerce_cart_totals_before_shippingrussian-post-for-dokan-marketplace.php:73
actionwoocommerce_review_order_before_cart_contentsrussian-post-for-dokan-marketplace.php:74
actionwoocommerce_pre_payment_completerussian-post-for-dokan-marketplace.php:76
actionwoocommerce_order_status_changedrussian-post-for-dokan-marketplace.php:77
filterwoocommerce_update_order_review_fragmentsrussian-post-for-dokan-marketplace.php:78
filterwoocommerce_admin_order_actionsrussian-post-for-dokan-marketplace.php:82
actiondokan_order_details_after_customer_inforussian-post-for-dokan-marketplace.php:83
filterwoocommerce_email_classesrussian-post-for-dokan-marketplace.php:84
actioninitrussian-post-for-dokan-marketplace.php:89
actionpost_rf_daily_eventrussian-post-for-dokan-marketplace.php:93

Scheduled Events 1

post_rf_daily_event
Maintenance & Trust

Фулфилмент от Почты России для маркетплейса Dokan Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedDec 14, 2022
PHP min version7.4
Downloads1K

Community Trust

Rating20/100
Number of ratings1
Active installs0
Developer Profile

Фулфилмент от Почты России для маркетплейса Dokan Developer Profile

Anton Drobyshev

7 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Фулфилмент от Почты России для маркетплейса Dokan

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/russian-post-for-dokan-marketplace/assets/css/backend_style.css/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/backend_script.js/wp-content/plugins/russian-post-for-dokan-marketplace/assets/css/frontend_style.css/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/frontend_script.js
Script Paths
/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/backend_script.js/wp-content/plugins/russian-post-for-dokan-marketplace/assets/js/frontend_script.js
Version Parameters
russian-post-for-dokan-marketplace/assets/css/backend_style.css?ver=russian-post-for-dokan-marketplace/assets/js/backend_script.js?ver=russian-post-for-dokan-marketplace/assets/css/frontend_style.css?ver=russian-post-for-dokan-marketplace/assets/js/frontend_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
russian-post-cancel-request-button
Data Attributes
data-id="cancel-order-request"
JS Globals
russian_post_params
REST Endpoints
/wp-json/russian-post-for-dokan-marketplace/v1/get-price
FAQ

Frequently Asked Questions about Фулфилмент от Почты России для маркетплейса Dokan