
Sözleşmeler Security & Risk Analysis
wordpress.org/plugins/sozlesmelerWordPress plugin to add legal documents like distance sales agreement to your WooCommerce store.
Is Sözleşmeler Safe to Use in 2026?
Generally Safe
Score 92/100Sözleşmeler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sozlesmeler" v2.7.0 plugin demonstrates a generally strong security posture based on the provided static analysis. It exhibits zero known vulnerabilities in its history, which is a significant positive indicator. Furthermore, the code analysis reveals a clean codebase with no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilizing prepared statements. The output escaping is also well-handled, with 87% of outputs properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The presence of nonce checks on some functions is also a good practice.
Despite these strengths, there are a few areas that prevent a perfect score. The complete absence of capability checks is a notable concern. While there are no reported AJAX handlers or REST API routes without authentication, the lack of capability checks on any potential entry points means that even if authentication is present, authorization might not be granularly enforced, potentially allowing unauthorized users to trigger unintended actions if other vulnerabilities were present or introduced later. The fact that there are no uncovered entry points (AJAX, REST API, shortcodes, cron) is excellent, suggesting a limited attack surface. However, the absence of capability checks on the existing nonce checks means that these protections are not as robust as they could be.
Overall, the plugin is well-coded and has a strong track record, indicating responsible development. The primary weakness lies in the absence of capability checks, which, while not presenting an immediate exploitable vulnerability based on this analysis, is a fundamental security control that should ideally be present to ensure robust authorization. The current score reflects its strong technical implementation and clean history but accounts for this missed security best practice.
Key Concerns
- Missing capability checks
- High percentage of properly escaped output
- All SQL queries use prepared statements
- No dangerous functions
- No file operations
- No external HTTP requests
- No unprotected AJAX handlers
- No unprotected REST API routes
- No shortcodes
- No cron events
- No known CVEs
- No taint analysis findings
Sözleşmeler Security Vulnerabilities
Sözleşmeler Code Analysis
Output Escaping
Data Flow Analysis
Sözleşmeler Attack Surface
WordPress Hooks 14
Maintenance & Trust
Sözleşmeler Maintenance & Trust
Maintenance Signals
Community Trust
Sözleşmeler Alternatives
Hezarfen – WooCommerce için Kargo Entegrasyonu – Sözleşmeler, Mahalle, İlçe, SMS
hezarfen-for-woocommerce
🚀 2 bin site! Kargo takip, ücretsiz Hepsijet Entegrasyonu (1-4 desi: 89,24TL+KDV - Hezarfen Pro gerekmez), Mesafeli Sözleşmeler, NetGSM sipariş SMS
WC Korkmaz Contract – Contracts for WooCommerce
wc-korkmaz-contract
Automatically builds, displays, and emails legally compliant contracts (PDF) on the WooCommerce checkout page.
WTC: Sözleşmeler, Kargo, SMS, İade, Form, OTP (SMS Doğrulama), Puan, Kupon Yönetimi
wtc-checkout
WC Turkiye: Contracts, Form Fields, District/Neighborhood Select, Auto Postcode, Cargo, SMS, OTP, Points, Coupons, Return and Dashboard Management.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Sözleşmeler Developer Profile
2 plugins · 1K total installs
How We Detect Sözleşmeler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sozlesmeler/css/stil.css/wp-content/plugins/sozlesmeler/js/woocontracts.js/wp-content/plugins/sozlesmeler/js/woocontractsadmin.js/wp-content/plugins/sozlesmeler/js/notify.min.js/wp-content/plugins/sozlesmeler/css/adminstil.css/wp-content/plugins/sozlesmeler/js/woocontracts.js/wp-content/plugins/sozlesmeler/js/woocontractsadmin.js/wp-content/plugins/sozlesmeler/js/notify.min.jssozlesmeler/js/woocontracts.js?ver=sozlesmeler/js/woocontractsadmin.js?ver=sozlesmeler/js/notify.min.js?ver=sozlesmeler/css/stil.css?ver=sozlesmeler/css/adminstil.css?ver=HTML / DOM Fingerprints
musteriadmusterisoyadmusterifirmamusteriadres1musteriadres2musteripostamusteriilcemusteriil+15 moreid="woocontracts-tab-content"id="woocontracts-settings"WCTR_VER[fatura-isim][fatura-firma][fatura-adres][tc-kimlik-no]