
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Security & Risk Analysis
wordpress.org/plugins/kosteams-payments-for-yandexAccept payments via Yandex Pay, Yandex Split, or a combination of both. Increase conversion with flexible payment options using the KosTeams plugin.
Is KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of "kosteams-payments-for-yandex" v2.0.6 appears to be strong based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, and the consistent use of prepared statements and proper output escaping are excellent security practices. The plugin also demonstrates good user access control with capability checks in place.
However, a significant concern arises from the complete lack of nonce checks across all identified entry points. While the static analysis reported zero AJAX handlers and REST API routes, the presence of file operations and external HTTP requests suggests potential areas where unauthorized actions could be initiated without proper verification. The fact that there are no recorded vulnerabilities is a positive indicator, suggesting the developers have been diligent. Nevertheless, the lack of comprehensive security controls on potential execution paths presents an inherent risk.
In conclusion, while the plugin exhibits sound coding practices regarding data handling and output, the absence of nonce checks is a notable weakness. This, combined with the presence of file operations and external HTTP requests, creates a potential attack surface that is not adequately protected against unauthorized execution. The vulnerability history is a strength, but it does not negate the need for robust security measures on all code paths.
Key Concerns
- Lack of nonce checks on potential entry points
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Security Vulnerabilities
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Code Analysis
Output Escaping
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Attack Surface
WordPress Hooks 15
Maintenance & Trust
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Alternatives
Sezzle Woocommerce Payment
sezzle-woocommerce-payment
Sezzle is an alternative payment platform that increases sales and basket sizes by enabling your customers to 'buy now and pay later' with i …
Netgíró Payment Gateway for WooCommerce
netgiro-payment-gateway-for-woocommerce
Offer your customers Netgíró’s quick, secure, and streamlined payment solution directly in your WooCommerce store.
Yandex Pay and Split
yandex-pay-and-split
The official Yandex Pay and Split module for WooCommerce
Split Pay – Stripe Connect Split Payments & Multi-Vendor Marketplace for WooCommerce
bsd-woo-stripe-connect-split-pay
Split payments made in WooCommerce stores between multiple Stripe Connected Accounts and a Stripe Platform Account.
Limepay WooCommerce Gateway
limepay-woocommerce-gateway
Woo-Commerce gateway extension to support Limepay payments
KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Developer Profile
2 plugins · 250 total installs
How We Detect KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kosteams-payments-for-yandex/assets/css/yandex-pay-checkout.css/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-split-blocks.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-split-blocks.jskosteams-payments-for-yandex/assets/css/yandex-pay-checkout.css?ver=kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js?ver=kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js?ver=kosteams-payments-for-yandex/assets/js/yandex-split-blocks.js?ver=HTML / DOM Fingerprints
yandex-pay-buttonyandex_pay_gateway<!-- Yandex Pay Button --><!-- Yandex Split Button -->data-yandex-pay-button-iddata-yandex-pay-amountdata-yandex-pay-currencyYandexPayCheckoutwc_kosteams_yandex_pay_params/wp-json/kosteams-payments-for-yandex/v1/payment-status[yandex_pay_button]