
Mihdan: Dialogs For Yandex Security & Risk Analysis
wordpress.org/plugins/mihdan-yandex-dialogsПлагин добавляет виджет Яндекс.Диалоги на сайт.
Is Mihdan: Dialogs For Yandex Safe to Use in 2026?
Generally Safe
Score 85/100Mihdan: Dialogs For Yandex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mihdan-yandex-dialogs" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical taint flows, dangerous functions, direct SQL queries, or external HTTP requests is highly positive. Furthermore, the fact that all observed SQL queries utilize prepared statements indicates good database interaction practices.
However, there are notable areas of concern. The low percentage of properly escaped output (34%) is a significant weakness. This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, where user-supplied data, if not sanitized before being displayed, could be executed in the browser of other users. The complete lack of nonce and capability checks, coupled with zero entry points with authentication checks, also raises questions about how the plugin handles sensitive operations or data, even though the attack surface appears to be zero based on the reported entry points.
Given the lack of historical vulnerabilities, it's difficult to infer long-term patterns. The current assessment leans towards a plugin that has good intentions regarding core security measures like database access and avoiding known dangerous functions, but has a critical oversight in output sanitization, which could lead to severe security issues if not addressed. The absence of a wider attack surface currently mitigates some risk, but the unescaped output remains a primary concern.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
Mihdan: Dialogs For Yandex Security Vulnerabilities
Mihdan: Dialogs For Yandex Code Analysis
Output Escaping
Mihdan: Dialogs For Yandex Attack Surface
WordPress Hooks 6
Maintenance & Trust
Mihdan: Dialogs For Yandex Maintenance & Trust
Maintenance Signals
Community Trust
Mihdan: Dialogs For Yandex Alternatives
Maps from Yandex for Elementor
mihdan-elementor-yandex-maps
Yandex Maps widget for Elementor
Yandex.Zen PostGrid
display-yandex-zen-postgrid
The plugin allows you to display the last record from your ZEN channel
TI Stat
ti-stat
Plugins shows charts from Yandex.Metrika on page.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Mihdan: Dialogs For Yandex Developer Profile
11 plugins · 31K total installs
How We Detect Mihdan: Dialogs For Yandex
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mihdan-yandex-dialogs/assets/js/mihdan-yandex-dialogs.js/wp-content/plugins/mihdan-yandex-dialogs/assets/css/mihdan-yandex-dialogs.cssmihdan-yandex-dialogs/assets/js/mihdan-yandex-dialogs.js?ver=mihdan-yandex-dialogs/assets/css/mihdan-yandex-dialogs.css?ver=HTML / DOM Fingerprints
mihdan-yandex-dialogs-blockMihdanYandexDialogs[mihdan_yandex_dialogs id=