wpShopGermany IT-RECHT KANZLEI Security & Risk Analysis

wordpress.org/plugins/wpshopgermany-it-recht-kanzlei

Mit Hilfe dieses Plugins ist es möglich deutsche rechtssichere Texte (für Shops) über eine API zu aktualisieren.

600 active installs v2.2 PHP + WP 3.0+ Updated Jul 18, 2025
agbimpressumit-recht-kanzlei-munchenrechtstexteshops
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is wpShopGermany IT-RECHT KANZLEI Safe to Use in 2026?

Generally Safe

Score 99/100

wpShopGermany IT-RECHT KANZLEI has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 27, 2025Updated 8mo ago
Risk Assessment

The "wpshopgermany-it-recht-kanzlei" plugin v2.2 presents a mixed security posture. On the positive side, the static analysis shows a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. The use of prepared statements for all SQL queries is also a strong indicator of good security practices. However, the code analysis does reveal some areas of concern. A significant portion (22%) of the output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unsanitized data is displayed to users. Furthermore, there is one identified flow with an unsanitized path, although it is not classified as critical or high severity, it still represents a potential risk. The plugin's vulnerability history is concerning, with two medium-severity CVEs previously identified, including Cross-Site Request Forgery (CSRF) and XSS. Although there are currently no unpatched vulnerabilities, the past occurrences of these common web application security flaws suggest a recurring pattern that warrants vigilance.

In conclusion, while the plugin has made strides in securing its direct entry points and database interactions, the unescaped output and unsanitized path flow indicate potential vulnerabilities that require attention. The history of past security issues, particularly in common areas like CSRF and XSS, reinforces the need for ongoing security reviews and prompt patching of any newly discovered weaknesses. The lack of capability checks is also a point of weakness, as it implies that any authenticated user might be able to access certain functionalities.

Key Concerns

  • Unescaped output detected
  • Flow with unsanitized path
  • Medium severity vulnerability history (x2)
  • Lack of capability checks
Vulnerabilities
2

wpShopGermany IT-RECHT KANZLEI Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-30804medium · 4.3Cross-Site Request Forgery (CSRF)

wpShopGermany IT-RECHT KANZLEI <= 2.0 - Cross-Site Request Forgery

Mar 27, 2025 Patched in 2.1 (7d)
CVE-2023-37993medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

wpShopGermany IT-RECHT KANZLEI <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 19, 2023 Patched in 1.8 (188d)
Code Analysis
Analyzed Mar 16, 2026

wpShopGermany IT-RECHT KANZLEI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
2
7 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

78% escaped9 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
wp_loaded (classes\wpsg_itrecht.class.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

wpShopGermany IT-RECHT KANZLEI Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwoocommerce_email_attachmentsclasses\wpsg_itrecht.class.php:319
filterwpsg_sendMailclasses\wpsg_itrecht.class.php:320
actionadmin_menuwpshopgermany-itrecht.php:37
actionwp_loadedwpshopgermany-itrecht.php:146
Maintenance & Trust

wpShopGermany IT-RECHT KANZLEI Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJul 18, 2025
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

wpShopGermany IT-RECHT KANZLEI Developer Profile

maennchen1.de

5 plugins · 2K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect wpShopGermany IT-RECHT KANZLEI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpshopgermany-it-recht-kanzlei/css/wpsgit.css/wp-content/plugins/wpshopgermany-it-recht-kanzlei/js/wpsgit.js
Script Paths
/wp-content/plugins/wpshopgermany-it-recht-kanzlei/js/wpsgit.js
Version Parameters
wpshopgermany-it-recht-kanzlei/css/wpsgit.css?ver=wpshopgermany-it-recht-kanzlei/js/wpsgit.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpsgit-contentwpsgit-headlinewpsgit-text
Data Attributes
wpsgit_submitwpsgit_action
Shortcode Output
[wpsg_itrecht_agb][wpsg_itrecht_datenschutz][wpsg_itrecht_widerruf][wpsg_itrecht_impressum]
FAQ

Frequently Asked Questions about wpShopGermany IT-RECHT KANZLEI