Ua Marketplace Security & Risk Analysis

wordpress.org/plugins/ua-marketplace

Синхронізуйтесь з українськими маркетплейсами швидко та зручно.

100 active installs v1.4.15 PHP 7.0+ WP 5.0+ Updated Jan 23, 2026
ecommerce%d1%80%d0%be%d0%b7%d0%b5%d1%82%d0%ba%d0%b0rozetkawoocommercexml
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ua Marketplace Safe to Use in 2026?

Generally Safe

Score 100/100

Ua Marketplace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'ua-marketplace' plugin version 1.4.16 exhibits a generally positive security posture with no known vulnerabilities or critical taint flows. The presence of nonce and capability checks on its two AJAX entry points is a good practice, as is the absence of dangerous functions and bundled libraries. However, there are notable areas for improvement. A significant concern is the complete lack of prepared statements for its SQL queries, which presents a high risk of SQL injection vulnerabilities. Additionally, less than half of the output escaping is properly implemented, leaving room for Cross-Site Scripting (XSS) attacks. While the vulnerability history is clean, this does not negate the inherent risks identified in the static analysis. The plugin has strengths in its limited attack surface and authorization checks, but the lack of prepared SQL statements and insufficient output escaping are critical weaknesses that require immediate attention.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

Ua Marketplace Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ua Marketplace Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
52
47 escaped
Nonce Checks
3
Capability Checks
1
File Operations
13
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

47% escaped99 total outputs
Attack Surface

Ua Marketplace Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_mrkvuamp_collation_actioninc\Base\AjaxHandler.php:21
authwp_ajax_mrkvuamp_promuaxml_actioninc\Base\AjaxHandler.php:22
WordPress Hooks 26
actionadmin_menuinc\Api\SettingsApi.php:23
actionadmin_initinc\Api\SettingsApi.php:27
actionadmin_enqueue_scriptsinc\Base\Enqueue.php:17
filterscript_loader_taginc\Base\Enqueue.php:18
actionadmin_headinc\Base\WPCRONHandler.php:41
actionmrkvuamp_update_xml_hookinc\Base\WPCRONHandler.php:42
actionadmin_headinc\Base\WPCRONHandler.php:54
actionmrkvuamp_update_xml_hook_promuainc\Base\WPCRONHandler.php:55
filtercron_schedulesinc\Base\WPCRONHandler.php:63
actionadmin_headinc\Base\WPCRONHandler.php:64
actionmrkvuamp_partial_update_xml_hook_promuainc\Base\WPCRONHandler.php:65
filtermanage_edit-product_columnsinc\Core\WCShop\EditProduct\ExtraProductSettings.php:31
filterwoocommerce_product_data_tabsinc\Core\WCShop\EditProduct\ExtraProductSettings.php:34
actionwoocommerce_product_data_panelsinc\Core\WCShop\EditProduct\ExtraProductSettings.php:35
actionwoocommerce_process_product_metainc\Core\WCShop\EditProduct\ExtraProductSettings.php:36
actionwoocommerce_variation_options_pricinginc\Core\WCShop\EditProduct\ExtraVariationSettings.php:30
actionwoocommerce_save_product_variationinc\Core\WCShop\EditProduct\ExtraVariationSettings.php:31
filtermanage_product_posts_columnsinc\Core\WCShop\EditProduct\QuickEditProductSettings.php:35
actionmanage_product_posts_custom_columninc\Core\WCShop\EditProduct\QuickEditProductSettings.php:36
actionmanage_product_posts_custom_columninc\Core\WCShop\EditProduct\QuickEditProductSettings.php:37
actionquick_edit_custom_boxinc\Core\WCShop\EditProduct\QuickEditProductSettings.php:39
actionsave_postinc\Core\WCShop\EditProduct\QuickEditProductSettings.php:40
actionadmin_footerinc\Core\WCShop\EditProduct\QuickEditProductSettings.php:42
filterpost_row_actionsinc\Core\WCShop\EditProduct\QuickEditProductSettings.php:43
actionadmin_noticesinc\Pages\Dashboard.php:39
actionbefore_woocommerce_initmorkvawrs-plugin.php:26

Scheduled Events 3

mrkvuamp_update_xml_hook
mrkvuamp_partial_update_xml_hook_promua
mrkvuamp_update_xml_hook_promua
Maintenance & Trust

Ua Marketplace Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 23, 2026
PHP min version7.0
Downloads7K

Community Trust

Rating86/100
Number of ratings11
Active installs100
Developer Profile

Ua Marketplace Developer Profile

Ihor Kit

14 plugins · 3K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Ua Marketplace

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ua-marketplace/assets/mrkvmpstyle.min.css/wp-content/plugins/ua-marketplace/assets/mrkvmpscript.min.js
Script Paths
/wp-content/plugins/ua-marketplace/assets/mrkvmpscript.min.js
Version Parameters
ua-marketplace/assets/mrkvmpstyle.min.css?ver=ua-marketplace/assets/mrkvmpscript.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
mrkvuamp_wrap
HTML Comments
<!-- If this file is called directly, abort. -->
Data Attributes
data-plugin_dir_url
JS Globals
mrkvuamp_script_vars
FAQ

Frequently Asked Questions about Ua Marketplace