XML for E-Katalog (ek.ua) Security & Risk Analysis

wordpress.org/plugins/xml-e-katalog

Creates a XML-feed to upload to E-Katalog (https://ek.ua).

10 active installs v1.0.0 PHP + WP 5.0+ Updated Jan 12, 2021
e-katalogekekatalogmarketxml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is XML for E-Katalog (ek.ua) Safe to Use in 2026?

Generally Safe

Score 85/100

XML for E-Katalog (ek.ua) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "xml-e-katalog" v1.0.0 plugin exhibits a generally good security posture based on the static analysis provided. The absence of any reported CVEs and the fact that all detected SQL queries utilize prepared statements are strong indicators of adherence to secure coding practices. Furthermore, the complete lack of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. The absence of any taint analysis findings or dangerous function calls further bolsters this assessment, suggesting no immediate exploitable vulnerabilities in these areas.

However, there are areas of concern that prevent a perfect score. The plugin performs file operations, which inherently carry some risk if not handled with extreme care, especially without clear evidence of sanitization or access control. More notably, only 50% of output escaping is properly implemented, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization. The complete lack of nonce checks and capability checks, while understandable given the limited entry points, also means that if any entry points were to be added in future versions, these critical security layers would be missing by default, posing a risk for future development.

In conclusion, "xml-e-katalog" v1.0.0 appears to be a relatively secure plugin in its current state, with a very small attack surface and no known vulnerabilities or critical code signals. Its strengths lie in its minimal exposed functionality and proper SQL handling. The primary weaknesses are the potential for XSS due to incomplete output escaping and the inherent risks associated with file operations without further context. The absence of nonce and capability checks is a notable omission that could become a risk in future updates.

Key Concerns

  • Incomplete output escaping
  • Presence of file operations
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

XML for E-Katalog (ek.ua) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

XML for E-Katalog (ek.ua) Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

XML for E-Katalog (ek.ua) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped14 total outputs
Attack Surface

XML for E-Katalog (ek.ua) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterset-screen-optioninc/classes/controllers/AbstractController.php:42
actionadmin_menuinc/classes/controllers/AbstractController.php:43
actionadmin_enqueue_scriptsinc/classes/controllers/AbstractController.php:44
actionadmin_noticesinc/classes/controllers/GenerateXMLController.php:52
actionadmin_noticesinc/classes/controllers/GenerateXMLController.php:55
actionplugins_loadedinc/hooks.php:23
filterwp_dropdown_catsinc/hooks.php:48
filterwoocommerce_product_data_store_cpt_get_products_queryinc/hooks.php:68
Maintenance & Trust

XML for E-Katalog (ek.ua) Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 12, 2021
PHP min version
Downloads925

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

XML for E-Katalog (ek.ua) Developer Profile

nadavitradesystems

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XML for E-Katalog (ek.ua)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xml-e-katalog/assets/css/ekatwoo.css/wp-content/plugins/xml-e-katalog/assets/css/admin.css
Version Parameters
ekatwoo.css?ver=admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about XML for E-Katalog (ek.ua)