
Zverejniť.sk Security & Risk Analysis
wordpress.org/plugins/zverejnit-skPlugin umožňuje vložiť na stránku tabuľky s dokumentami - objednávkami, zmluvami či faktúrami a tiež pridá možnosť vkladať dokumenty do systému Zverej …
Is Zverejniť.sk Safe to Use in 2026?
Generally Safe
Score 85/100Zverejniť.sk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zverejnit-sk" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities or CVEs. The attack surface is minimal with only one shortcode and no AJAX, REST API routes, or cron events that are immediately apparent as unprotected entry points.
However, a significant concern arises from the complete lack of output escaping for all identified outputs. This means that any data processed or displayed by the plugin, even if it originates from a trusted source, is not being sanitized before being rendered in the browser. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into the plugin's output. Additionally, the absence of nonce checks on the single entry point, though it has a capability check, is a potential weakness that could be exploited in conjunction with other vulnerabilities.
Given the plugin's clean vulnerability history and avoidance of common pitfalls like raw SQL or dangerous functions, it appears to be developed with some security awareness. However, the unescaped output represents a critical oversight that significantly increases the risk profile. The presence of a capability check on the shortcode is a mitigating factor, but it does not address the fundamental issue of output sanitation.
Key Concerns
- 0% output escaping
- No nonce checks on entry point
Zverejniť.sk Security Vulnerabilities
Zverejniť.sk Release Timeline
Zverejniť.sk Code Analysis
Output Escaping
Zverejniť.sk Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Zverejniť.sk Maintenance & Trust
Maintenance Signals
Community Trust
Zverejniť.sk Alternatives
ING Księgowość
ing-ksiegowosc
Niech faktury za zakupy Twoich klientów wystawiają się automatycznie! Wtyczka pozwala na powiązanie sklepu z kontem firmy w aplikacji ING Księgowość
GTU dla Faktur WooCommerce
flexible-invoices-gtu
Support for goods and services designations (GTU codes) on documents created by the Flexible Invoices for WooCommerce PRO plugin.
PayU Purchase
estrx-payu-purchase
Plug-in do a purchase in case you have PayU account
Zverejniť.sk Developer Profile
1 plugin · 0 total installs
How We Detect Zverejniť.sk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zverejnit-sk/zverejnit-sk.phphttps://data.zverejnit.sk/HTML / DOM Fingerprints
zverejnit-wrapzverejnit-titlezverejnitskzverejnitsk-fakturyzverejnitsk-zmluvyzverejnitsk-objednavkypinf-test-configdata-uiddata-secretsavedPinfConf[zverejnit dokumenty=faktury][zverejnit dokumenty=zmluvy][zverejnit dokumenty=objednavky]