Kybernaut IČO DIČ Security & Risk Analysis

wordpress.org/plugins/woolab-ic-dic

Adds Company & VAT numbers (IČO & DIČ & IČ DPH) to WooCommerce billing fields and verifies if data are correct.

3K active installs v1.10.2 PHP 7.3+ WP 4.6+ Updated Nov 28, 2025
dicicoicic-dphvat-number
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kybernaut IČO DIČ Safe to Use in 2026?

Generally Safe

Score 100/100

Kybernaut IČO DIČ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "woolab-ic-dic" plugin v1.10.2 presents a mixed security posture. While it demonstrates good practices in SQL query handling and a commendable rate of output escaping, significant concerns arise from its attack surface and the presence of dangerous functions. The plugin exposes four AJAX handlers, all of which lack authentication checks, creating a substantial entry point for potential attackers. Furthermore, the use of the `unserialize` function is a critical risk, as it can lead to remote code execution if provided with malicious input. Although the plugin has no recorded vulnerability history, this does not guarantee its current safety, especially given the identified code-level risks. The absence of known CVEs might indicate recent development or a lack of past scrutiny, but the current static analysis reveals clear weaknesses that need immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Dangerous function: unserialize
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Kybernaut IČO DIČ Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kybernaut IČO DIČ Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
4
14 escaped
Nonce Checks
1
Capability Checks
3
File Operations
4
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

unserialize$data = unserialize($contents, ['allowed_classes' => [Period::class, DateTimeImmutable::class]]);deps\ibericode\vat\src\Rates.php:58

Output Escaping

78% escaped18 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
woolab_icdic_checkout_field_process (includes\filters-actions.php:153)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Kybernaut IČO DIČ Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

noprivwp_ajax_woolab_icdic_notice_dismissincludes\admin-notice.php:16
authwp_ajax_woolab_icdic_notice_dismissincludes\admin-notice.php:17
noprivwp_ajax_ajaxAreswoolab-ic-dic.php:129
authwp_ajax_ajaxAreswoolab-ic-dic.php:130
WordPress Hooks 32
actionadmin_noticesincludes\admin-notice.php:3
filterfc_hide_optional_fields_skip_listincludes\compatibility\fluidcheckout.php:13
filterapifw_invoice_custom_billing_fieldsincludes\compatibility\pdf-invoices-and-packing-slips-for-woocommerce.php:45
filtersf_client_dataincludes\compatibility\superfaktura.php:10
filterwoocommerce_general_settingsincludes\settings.php:3
actionadmin_initwoolab-ic-dic.php:54
actionadmin_noticeswoolab-ic-dic.php:55
filterwoocommerce_billing_fieldswoolab-ic-dic.php:95
filterwoocommerce_checkout_fieldswoolab-ic-dic.php:96
actionwoocommerce_checkout_processwoolab-ic-dic.php:97
filterwoocommerce_my_account_my_address_formatted_addresswoolab-ic-dic.php:98
filterwoocommerce_localisation_address_formatswoolab-ic-dic.php:99
filterwoocommerce_formatted_address_replacementswoolab-ic-dic.php:100
filterwoocommerce_order_formatted_billing_addresswoolab-ic-dic.php:101
filterwoocommerce_customer_meta_fieldswoolab-ic-dic.php:102
filterwoocommerce_admin_billing_fieldswoolab-ic-dic.php:103
actionwoocommerce_process_shop_order_metawoolab-ic-dic.php:104
filterdefault_checkout_billing_iscompwoolab-ic-dic.php:105
actioninitwoolab-ic-dic.php:106
actionwoocommerce_checkout_update_order_reviewwoolab-ic-dic.php:107
actionwoocommerce_checkout_update_order_metawoolab-ic-dic.php:108
actionmanage_shop_order_posts_custom_columnwoolab-ic-dic.php:109
actionwoocommerce_shop_order_list_table_custom_columnwoolab-ic-dic.php:110
actionwoocommerce_admin_order_data_after_billing_addresswoolab-ic-dic.php:111
actionwoocommerce_email_order_detailswoolab-ic-dic.php:112
filterwoocommerce_found_customer_detailswoolab-ic-dic.php:115
filterwoocommerce_ajax_get_customer_detailswoolab-ic-dic.php:117
filterplugin_row_metawoolab-ic-dic.php:120
actionadmin_enqueue_scriptswoolab-ic-dic.php:123
actionwp_enqueue_scriptswoolab-ic-dic.php:126
actionplugins_loadedwoolab-ic-dic.php:134
actionbefore_woocommerce_initwoolab-ic-dic.php:225
Maintenance & Trust

Kybernaut IČO DIČ Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 28, 2025
PHP min version7.3
Downloads47K

Community Trust

Rating100/100
Number of ratings38
Active installs3K
Developer Profile

Kybernaut IČO DIČ Developer Profile

Karolina Vyskocilova

5 plugins · 24K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
993 days
View full developer profile
Detection Fingerprints

How We Detect Kybernaut IČO DIČ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woolab-ic-dic/assets/js/public.js/wp-content/plugins/woolab-ic-dic/assets/css/style.css
Script Paths
/wp-content/plugins/woolab-ic-dic/assets/js/public.js
Version Parameters
woolab-ic-dic/assets/js/public.js?ver=woolab-ic-dic/assets/css/style.css?ver=

HTML / DOM Fingerprints

JS Globals
window.woolab
REST Endpoints
/wp-json/woolab-ic-dic/v1/ares/
FAQ

Frequently Asked Questions about Kybernaut IČO DIČ