Đẩy Thông Báo Woocommerce tới Telegram Security & Risk Analysis

wordpress.org/plugins/wc-telegram-bot

Đây là plugin giúp đẩy thông báo đơn hàng Woocommerce qua Telegram BOT. Phát triển bởi Tám Tinh Tế.

100 active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated May 1, 2021
telegram-botwoocommercewoocommerce-to-telegram
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Đẩy Thông Báo Woocommerce tới Telegram Safe to Use in 2026?

Generally Safe

Score 85/100

Đẩy Thông Báo Woocommerce tới Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The wc-telegram-bot v1.0.1 plugin presents a mixed security profile. On the positive side, the absence of any recorded vulnerabilities or CVEs, coupled with a lack of critical taint flows and dangerous function usage, suggests a generally stable codebase. The plugin also correctly utilizes prepared statements for all SQL queries, which is a strong security practice.

However, several areas raise concerns. The low percentage of properly escaped output (23%) indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While no direct XSS is confirmed by the static analysis, this widespread issue means that user-supplied data, if processed by the plugin without adequate sanitization, could be injected and executed in users' browsers. Furthermore, the complete absence of nonce checks and capability checks, despite having an external HTTP request, leaves the plugin open to potential Cross-Site Request Forgery (CSRF) attacks if the external request involves sensitive operations or data, and could allow unauthorized users to trigger unintended actions.

In conclusion, while the plugin has avoided historical security incidents and employs good SQL practices, the high proportion of unescaped output and the missing authentication/authorization checks on potential entry points are significant weaknesses that warrant attention. The plugin's strengths lie in its lack of historical issues and sound SQL handling, but its weaknesses in output sanitization and authorization present tangible risks.

Key Concerns

  • Low percentage of output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Đẩy Thông Báo Woocommerce tới Telegram Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Đẩy Thông Báo Woocommerce tới Telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

23% escaped22 total outputs
Attack Surface

Đẩy Thông Báo Woocommerce tới Telegram Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuwc-telegram-bot.php:40
actionadmin_initwc-telegram-bot.php:41
actionadmin_enqueue_scriptswc-telegram-bot.php:42
actionwoocommerce_thankyouwc-telegram-bot.php:45
actionwoocommerce_order_status_changedwc-telegram-bot.php:53
Maintenance & Trust

Đẩy Thông Báo Woocommerce tới Telegram Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 1, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating84/100
Number of ratings5
Active installs100
Developer Profile

Đẩy Thông Báo Woocommerce tới Telegram Developer Profile

Tám Tinh Tế

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Đẩy Thông Báo Woocommerce tới Telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-telegram-bot/assets/css/admin.css/wp-content/plugins/wc-telegram-bot/assets/js/admin.js
Script Paths
/wp-content/plugins/wc-telegram-bot/assets/js/admin.js

HTML / DOM Fingerprints

CSS Classes
woo_setting_mess
Data Attributes
name="wctelegrambot_options[enable_woo]"name="wctelegrambot_options[order_creat]"name="wctelegrambot_options[order_creat_mess]"name="wctelegrambot_options[woo_status_complete]"name="wctelegrambot_options[woo_status_complete_mess]"
FAQ

Frequently Asked Questions about Đẩy Thông Báo Woocommerce tới Telegram