KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Security & Risk Analysis

wordpress.org/plugins/kosteams-payments-for-yandex

Accept payments via Yandex Pay, Yandex Split, or a combination of both. Increase conversion with flexible payment options using the KosTeams plugin.

50 active installs v2.0.6 PHP 8.0.0+ WP 6.0+ Updated Mar 5, 2026
installmentspaypaymentssplityandex
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The security posture of "kosteams-payments-for-yandex" v2.0.6 appears to be strong based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, and the consistent use of prepared statements and proper output escaping are excellent security practices. The plugin also demonstrates good user access control with capability checks in place.

However, a significant concern arises from the complete lack of nonce checks across all identified entry points. While the static analysis reported zero AJAX handlers and REST API routes, the presence of file operations and external HTTP requests suggests potential areas where unauthorized actions could be initiated without proper verification. The fact that there are no recorded vulnerabilities is a positive indicator, suggesting the developers have been diligent. Nevertheless, the lack of comprehensive security controls on potential execution paths presents an inherent risk.

In conclusion, while the plugin exhibits sound coding practices regarding data handling and output, the absence of nonce checks is a notable weakness. This, combined with the presence of file operations and external HTTP requests, creates a potential attack surface that is not adequately protected against unauthorized execution. The vulnerability history is a strength, but it does not negate the need for robust security measures on all code paths.

Key Concerns

  • Lack of nonce checks on potential entry points
Vulnerabilities
None known

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionwoocommerce_api_kosteams-payments-for-yandexincludes\class-gateway.php:59
actionadmin_enqueue_scriptsincludes\class-gateway.php:62
filterwoocommerce_payment_gateway_supportsincludes\class-refund-handler.php:41
actionkosteams_payments_for_yandex_webhook_operation_status_updatedincludes\class-refund-handler.php:44
actionplugins_loadedkosteams-payments-for-yandex.php:70
actionplugins_loadedkosteams-payments-for-yandex.php:71
filterplugin_action_linkskosteams-payments-for-yandex.php:78
filterplugin_row_metakosteams-payments-for-yandex.php:79
actionadmin_noticeskosteams-payments-for-yandex.php:123
filterwoocommerce_payment_gatewayskosteams-payments-for-yandex.php:172
actionwoocommerce_blocks_loadedkosteams-payments-for-yandex.php:179
actioninitkosteams-payments-for-yandex.php:186
filterquery_varskosteams-payments-for-yandex.php:187
actionadmin_menukosteams-payments-for-yandex.php:194
actionwoocommerce_blocks_payment_method_type_registrationkosteams-payments-for-yandex.php:247
Maintenance & Trust

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version8.0.0
Downloads66K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce Developer Profile

KosTeams

2 plugins · 250 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kosteams-payments-for-yandex/assets/css/yandex-pay-checkout.css/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-split-blocks.js
Script Paths
/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js/wp-content/plugins/kosteams-payments-for-yandex/assets/js/yandex-split-blocks.js
Version Parameters
kosteams-payments-for-yandex/assets/css/yandex-pay-checkout.css?ver=kosteams-payments-for-yandex/assets/js/yandex-pay-checkout.js?ver=kosteams-payments-for-yandex/assets/js/yandex-pay-blocks.js?ver=kosteams-payments-for-yandex/assets/js/yandex-split-blocks.js?ver=

HTML / DOM Fingerprints

CSS Classes
yandex-pay-buttonyandex_pay_gateway
HTML Comments
<!-- Yandex Pay Button --><!-- Yandex Split Button -->
Data Attributes
data-yandex-pay-button-iddata-yandex-pay-amountdata-yandex-pay-currency
JS Globals
YandexPayCheckoutwc_kosteams_yandex_pay_params
REST Endpoints
/wp-json/kosteams-payments-for-yandex/v1/payment-status
Shortcode Output
[yandex_pay_button]
FAQ

Frequently Asked Questions about KosTeams Payments for Yandex Pay and Yandex Split for WooCommerce