Heureka

Official Heureka integration for WooCommerce

v1.1.0Heureka GroupUpdated Added 400 installs46% rating
22
Score
557
Errors
254
Warnings
+0
Change

Category Scores

Security0
Repo83
Performance96
Maintainability0

Issues to Review

Prioritized issue groups from the latest Plugin Check scan

811 findings

Security

472

8 issue groups

Maintainability

177

14 issue groups

I18n

94

3 issue groups

ERRORSecurityException output is not escapedAll output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '"Circular dependency detected while trying to resolve entry '{$entryName}'"'.253
Category
Security
Occurrences
253
Severity
error

Sample message

All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '"Circular dependency detected while trying to resolve entry '{$entryName}'"'.

ERRORSecurityOutput is not escapedAll output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$action'.70
Category
Security
Occurrences
70
Severity
error

Sample message

All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$action'.

ERRORI18nMissing Translators CommentA function call to __() with texts containing placeholders was found, but was not accompanied by a "translators:" comment on the line above to clarify the meaning of the placeholders.44
Category
I18n
Occurrences
44
Severity
error

Sample message

A function call to __() with texts containing placeholders was found, but was not accompanied by a "translators:" comment on the line above to clarify the meaning of the placeholders.

ERRORI18nText Domain MismatchMismatched text domain. Expected 'heureka' but got 'woocommerce'.44
Category
I18n
Occurrences
44
Severity
error

Sample message

Mismatched text domain. Expected 'heureka' but got 'woocommerce'.

WARNINGSecurityNonce verification recommendedProcessing form data without nonce verification.34
Category
Security
Occurrences
34
Severity
warning

Sample message

Processing form data without nonce verification.

WARNINGSecurityInput is not sanitizedDetected usage of a non-sanitized input variable: $_ENV[$variableName]33
Category
Security
Occurrences
33
Severity
warning

Sample message

Detected usage of a non-sanitized input variable: $_ENV[$variableName]

WARNINGSecurityRequest data is not unslashed$_GET['heureka_nonce'] not unslashed before sanitization. Use wp_unslash() or similar33
Category
Security
Occurrences
33
Severity
warning

Sample message

$_GET['heureka_nonce'] not unslashed before sanitization. Use wp_unslash() or similar

WARNINGMaintainabilityerror log var exportvar_export() found. Debug code should not normally be used in production.31
Category
Maintainability
Occurrences
31
Severity
warning

Sample message

var_export() found. Debug code should not normally be used in production.

WARNINGSecurityMissing nonce verificationProcessing form data without nonce verification.28
Category
Security
Occurrences
28
Severity
warning

Sample message

Processing form data without nonce verification.

ERRORMaintainabilitycurl curl setoptUsing cURL functions is highly discouraged. Use wp_remote_get() instead.26
Category
Maintainability
Occurrences
26
Severity
error

Sample message

Using cURL functions is highly discouraged. Use wp_remote_get() instead.

Show 15 more
WARNINGMaintainabilityNon-prefixed global variable25
Category
Maintainability
Occurrences
25
Severity
warning

Sample message

Global variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$__composer_autoload_files".

WARNINGMaintainabilityNon-prefixed hook name20
Category
Maintainability
Occurrences
20
Severity
warning

Sample message

Hook names invoked by a theme/plugin should start with the theme/plugin prefix. Found: "'wc_membership_plan_options_' . $this->tab['target']".

ERRORMaintainabilityMissing direct file access protection19
Category
Maintainability
Occurrences
19
Severity
error

Sample message

PHP file should prevent direct access. Add a check like: if ( ! defined( 'ABSPATH' ) ) exit;

WARNINGSecurityInput is not validated13
Category
Security
Occurrences
13
Severity
warning

Sample message

Detected usage of a possibly undefined superglobal array index: $_GET['heureka_nonce']. Check that the array index exists before using it.

ERRORMaintainabilitydate date9
Category
Maintainability
Occurrences
9
Severity
error

Sample message

date() is affected by runtime timezone changes which can cause date/time to be incorrectly displayed. Use gmdate() instead.

ERRORMaintainabilitycurl curl init9
Category
Maintainability
Occurrences
9
Severity
error

Sample message

Using cURL functions is highly discouraged. Use wp_remote_get() instead.

ERRORSecurityUnsafe printing function8
Category
Security
Occurrences
8
Severity
error

Sample message

All output should be run through an escaping function (like esc_html_e() or esc_attr_e()), found '_e'.

WARNINGMaintainabilityDynamic hook name6
Category
Maintainability
Occurrences
6
Severity
warning

Sample message

Hook names invoked by a theme/plugin should start with the theme/plugin prefix. Found: "$this->feed_name() . '_feed_data'".

WARNINGMaintainabilityerror log trigger error6
Category
Maintainability
Occurrences
6
Severity
warning

Sample message

trigger_error() found. Debug code should not normally be used in production.

ERRORMaintainabilityfile system operations fclose6
Category
Maintainability
Occurrences
6
Severity
error

Sample message

File operations should use WP_Filesystem methods instead of direct PHP filesystem calls. Found: fclose().

ERRORMaintainabilityfile system operations fwrite6
Category
Maintainability
Occurrences
6
Severity
error

Sample message

File operations should use WP_Filesystem methods instead of direct PHP filesystem calls. Found: fwrite().

ERRORI18nNon Singular String Literal Context6
Category
I18n
Occurrences
6
Severity
error

Sample message

The $context parameter must be a single text string literal. Found: $this->get_post_type_key()

ERRORMaintainabilityfile system operations fopen5
Category
Maintainability
Occurrences
5
Severity
error

Sample message

File operations should use WP_Filesystem methods instead of direct PHP filesystem calls. Found: fopen().

ERRORMaintainabilityunlink unlink5
Category
Maintainability
Occurrences
5
Severity
error

Sample message

unlink() is discouraged. Use wp_delete_file() to delete a file.

ERRORMaintainabilityBacktick operator found4
Category
Maintainability
Occurrences
4
Severity
error

Sample message

Use of the backtick operator is forbidden

External Connections

Potential connections found in static code analysis.

43 domains

Outbound calls

95

External assets

0

Incoming endpoints

0

Notable Domains

php.net6 · outbound
api.slack.com4 · outbound
php-fig.org4 · outbound
sluzby.heureka.cz4 · outbound
php-di.org3 · outbound
pushover.net3 · outbound

Platform / Reference Domains

github.com19 · platform/reference
gnu.org1 · platform/reference
w3.org1 · platform/reference

External Asset Domains

No external asset domains detected.

Incoming Endpoints

No public endpoints detected.

Score History

First score snapshot

v1.1.0

22

Latest

Findings
811
Errors
557
Warnings
254
Check
2.0.0

Relationship Map

Author, categories, issues, domains, and nearby plugins.

33 nodes

Related Plugins