
WC Korkmaz Contract – Contracts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-korkmaz-contractAutomatically builds, displays, and emails legally compliant contracts (PDF) on the WooCommerce checkout page.
Is WC Korkmaz Contract – Contracts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WC Korkmaz Contract – Contracts for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-korkmaz-contract plugin v2.3.8 presents a moderate security risk primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, the lack of authentication checks on all entry points creates a substantial attack surface. The presence of 8 AJAX handlers, all without authentication, means that any user, including unauthenticated ones, could potentially trigger these actions, leading to unintended consequences or exploitation if the AJAX handler logic is flawed.
The static analysis revealed two flows with unsanitized paths, though these are not classified as critical or high severity. This suggests potential for path traversal or similar vulnerabilities, even if not immediately exploitable in a critical manner. The absence of recorded CVEs and a clean vulnerability history is a positive sign, indicating that the plugin has not historically been a significant target for widespread exploitation. However, this does not negate the risks introduced by the current attack surface.
In conclusion, while the plugin scores well on SQL security and output escaping, and has a clean history, the unprotected AJAX handlers are a critical weakness. The potential for exploiting these entry points, combined with the identified unsanitized path flows, warrants careful consideration. The plugin's strengths in secure coding for database interactions and output are overshadowed by its failure to properly secure its primary interaction points with the user.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- No nonce checks
WC Korkmaz Contract – Contracts for WooCommerce Security Vulnerabilities
WC Korkmaz Contract – Contracts for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WC Korkmaz Contract – Contracts for WooCommerce Attack Surface
AJAX Handlers 8
WordPress Hooks 35
Maintenance & Trust
WC Korkmaz Contract – Contracts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WC Korkmaz Contract – Contracts for WooCommerce Alternatives
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
Checkout Field Manager (Checkout Manager) for WooCommerce
woocommerce-checkout-manager
Checkout Field Manager (Checkout Manager) for WooCommerce is the most advanced plugin to customize checkout fields on your WooCommerce checkout page.
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
WC Korkmaz Contract – Contracts for WooCommerce Developer Profile
2 plugins · 610 total installs
How We Detect WC Korkmaz Contract – Contracts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-korkmaz-contract/admin/css/korkmaz_contract-admin.css/wp-content/plugins/wc-korkmaz-contract/admin/js/korkmaz_contract-admin.js/wp-content/plugins/wc-korkmaz-contract/public/css/korkmaz_contract-public.css/wp-content/plugins/wc-korkmaz-contract/public/js/korkmaz_contract-public.js/wp-content/plugins/wc-korkmaz-contract/admin/js/korkmaz_contract-admin.js/wp-content/plugins/wc-korkmaz-contract/public/js/korkmaz_contract-public.jswc-korkmaz-contract/admin/css/korkmaz_contract-admin.css?ver=wc-korkmaz-contract/admin/js/korkmaz_contract-admin.js?ver=wc-korkmaz-contract/public/css/korkmaz_contract-public.css?ver=wc-korkmaz-contract/public/js/korkmaz_contract-public.js?ver=HTML / DOM Fingerprints
korkmaz-contract-fielddata-korkmaz-contract-idkorkmazContractData[korkmaz_contract_display_contract]