Zverejniť.sk Security & Risk Analysis

wordpress.org/plugins/zverejnit-sk

Plugin umožňuje vložiť na stránku tabuľky s dokumentami - objednávkami, zmluvami či faktúrami a tiež pridá možnosť vkladať dokumenty do systému Zverej …

0 active installs v1.0 PHP + WP 4.0+ Updated Jan 22, 2022
fakturyobjednavkypovinne-zverejnovaniezmluvyzverejnit-sk
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zverejniť.sk Safe to Use in 2026?

Generally Safe

Score 85/100

Zverejniť.sk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "zverejnit-sk" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities or CVEs. The attack surface is minimal with only one shortcode and no AJAX, REST API routes, or cron events that are immediately apparent as unprotected entry points.

However, a significant concern arises from the complete lack of output escaping for all identified outputs. This means that any data processed or displayed by the plugin, even if it originates from a trusted source, is not being sanitized before being rendered in the browser. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into the plugin's output. Additionally, the absence of nonce checks on the single entry point, though it has a capability check, is a potential weakness that could be exploited in conjunction with other vulnerabilities.

Given the plugin's clean vulnerability history and avoidance of common pitfalls like raw SQL or dangerous functions, it appears to be developed with some security awareness. However, the unescaped output represents a critical oversight that significantly increases the risk profile. The presence of a capability check on the shortcode is a mitigating factor, but it does not address the fundamental issue of output sanitation.

Key Concerns

  • 0% output escaping
  • No nonce checks on entry point
Vulnerabilities
None known

Zverejniť.sk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zverejniť.sk Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Zverejniť.sk Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Zverejniť.sk Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[zverejnit] zverejnit-sk.php:117
WordPress Hooks 3
actionadmin_menuzverejnit-sk.php:13
actionadmin_initzverejnit-sk.php:99
actioninitzverejnit-sk.php:114
Maintenance & Trust

Zverejniť.sk Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedJan 22, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zverejniť.sk Developer Profile

Pinf s.r.o.

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zverejniť.sk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zverejnit-sk/zverejnit-sk.php
Script Paths
https://data.zverejnit.sk/

HTML / DOM Fingerprints

CSS Classes
zverejnit-wrapzverejnit-titlezverejnitskzverejnitsk-fakturyzverejnitsk-zmluvyzverejnitsk-objednavkypinf-test-config
Data Attributes
data-uiddata-secret
JS Globals
savedPinfConf
Shortcode Output
[zverejnit dokumenty=faktury][zverejnit dokumenty=zmluvy][zverejnit dokumenty=objednavky]
FAQ

Frequently Asked Questions about Zverejniť.sk