Unofficial Yektanet Security & Risk Analysis

wordpress.org/plugins/unofficial-yektanet

اتصال وردپرس به یکتانت - راه‌حل کامل آنالیتیکس و ریتارگتینگ

30 active installs v2.0.0 PHP 8.1+ WP 6.0+ Updated Nov 5, 2025
ads%db%8c%da%a9%d8%aa%d8%a7%d9%86%d8%aayektanet%d8%aa%d8%a8%d9%84%db%8c%d8%ba%d8%a7%d8%aa%d8%b1%db%8c%d8%aa%d8%a7%d8%b1%da%af%d8%aa%db%8c%d9%86%da%af
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unofficial Yektanet Safe to Use in 2026?

Generally Safe

Score 100/100

Unofficial Yektanet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "unofficial-yektanet" plugin v2.0.0 exhibits a generally good security posture, with no recorded historical vulnerabilities. The static analysis reveals strong adherence to several security best practices, including the exclusive use of prepared statements for all SQL queries and a relatively high percentage of properly escaped outputs. Furthermore, the plugin has implemented nonce checks and capability checks on its entry points. The absence of file operations and the limited number of external HTTP requests are also positive indicators.

However, there are some areas for concern. The taint analysis identified three flows with unsanitized paths, which, despite being categorized as having no critical or high severity, represent potential avenues for data manipulation or unexpected behavior if these paths are reachable by user input. While the attack surface is small, the taint analysis findings warrant further investigation to ensure these unsanitized paths are not exploitable. The plugin's overall security is strong, but these identified taint flows represent a minor but important weakness that could be mitigated with more robust input sanitization.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Unofficial Yektanet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Unofficial Yektanet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
35
116 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

77% escaped151 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
send_product_data_to_ua (unofficialYektanet.php:1127)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Unofficial Yektanet Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_yektanet_change_timeframe_ajaxunofficialYektanet.php:1551
noprivwp_ajax_yektanet_change_timeframe_ajaxunofficialYektanet.php:1552
WordPress Hooks 18
actionplugins_loadedunofficialYektanet.php:47
actionadmin_menuunofficialYektanet.php:55
actionadmin_initunofficialYektanet.php:63
actionplugins_loadedunofficialYektanet.php:110
actionadmin_initunofficialYektanet.php:118
actionwoocommerce_single_product_summaryunofficialYektanet.php:149
actionwoocommerce_thankyouunofficialYektanet.php:150
actionwoocommerce_add_to_cartunofficialYektanet.php:151
actionwp_footerunofficialYektanet.php:152
actionwp_headunofficialYektanet.php:173
actionwp_dashboard_setupunofficialYektanet.php:177
actionwp_headunofficialYektanet.php:1020
actionadmin_enqueue_scriptsunofficialYektanet.php:1023
actionadmin_enqueue_scriptsunofficialYektanet.php:1090
actionwoocommerce_add_to_cartunofficialYektanet.php:1113
actionwoocommerce_order_status_changedunofficialYektanet.php:1185
actionwoocommerce_update_productunofficialYektanet.php:1294
actionwoocommerce_before_single_productunofficialYektanet.php:1295
Maintenance & Trust

Unofficial Yektanet Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedNov 5, 2025
PHP min version8.1
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Unofficial Yektanet Developer Profile

Mojtaba Amalian

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unofficial Yektanet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unofficial-yektanet/assets/css/style.css/wp-content/plugins/unofficial-yektanet/assets/js/script.js/wp-content/plugins/unofficial-yektanet/assets/js/yektanet.js
Script Paths
/wp-content/plugins/unofficial-yektanet/assets/js/script.js/wp-content/plugins/unofficial-yektanet/assets/js/yektanet.js
Version Parameters
unofficial-yektanet/assets/css/style.css?ver=unofficial-yektanet/assets/js/script.js?ver=unofficial-yektanet/assets/js/yektanet.js?ver=

HTML / DOM Fingerprints

CSS Classes
yektanet-logo
HTML Comments
<!-- Yektanet dashboard widget --><!-- Yektanet Custom Script Start --><!-- Yektanet Custom Script End --><!-- Yektanet App ID -->+4 more
Data Attributes
data-yektanet-product-iddata-yektanet-product-namedata-yektanet-product-pricedata-yektanet-product-categorydata-yektanet-product-branddata-yektanet-product-image+1 more
JS Globals
window.yektanet_analytics_trackerwindow.yektanet_app_idwindow.yektanet_ua_url
FAQ

Frequently Asked Questions about Unofficial Yektanet