VayaPin Connector Security & Risk Analysis

wordpress.org/plugins/vayapin

VayaPin Checkout Autofill for WooCommerce: one-click address autofill with GPS-precise VayaPin codes. Free plugin; API token from VayaPin.

0 active installs v2.1.1 PHP 7.4+ WP 6.0+ Updated Jun 19, 2026
addressautofillcheckoutvayapinwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VayaPin Connector Safe to Use in 2026?

Generally Safe

Score 100/100

VayaPin Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The Vayapin plugin version 1.0.0 exhibits a generally strong security posture, largely due to its diligent use of prepared statements for SQL queries and robust output escaping, with 98% of outputs being properly sanitized. The absence of known vulnerabilities and CVEs in its history further reinforces this positive outlook, suggesting a history of secure development and maintenance. The plugin effectively limits its attack surface by securing all its AJAX handlers, and the lack of shortcodes, cron events, and REST API routes contributes to a smaller potential exploit landscape.

However, a few areas warrant attention. The presence of three taint flows with unsanitized paths, although not classified as critical or high severity, indicates potential risks that should be investigated and remediated. While no direct SQL injection is evident, the existence of these unsanitized paths could be a precursor to such vulnerabilities if data is not handled with extreme care at specific points within these flows. Additionally, while the plugin has 3 nonce checks, the complete absence of capability checks on its entry points (AJAX handlers) is a significant concern, as it means any authenticated user, regardless of their role or permissions, could potentially trigger these actions, opening the door for privilege escalation or unauthorized operations.

In conclusion, Vayapin v1.0.0 demonstrates good fundamental security practices, particularly in data sanitization and database interaction. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the identified unsanitized taint flows and the critical omission of capability checks on its AJAX endpoints represent notable weaknesses that require immediate attention to ensure a truly secure plugin.

Key Concerns

  • Missing capability checks on entry points
  • Taint flows with unsanitized paths
Vulnerabilities
None known

VayaPin Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

VayaPin Connector Release Timeline

v2.1.1Current
v2.1.0
v2.0.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

VayaPin Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
53 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

98% escaped54 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
vayapin_connector_select2_search_callback (framework\ajax-methods.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

VayaPin Connector Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_vayapin_select2_searchframework\ajax-methods.php:30
noprivwp_ajax_vayapin_select2_searchframework\ajax-methods.php:31
authwp_ajax_vayapin_checkout_fillframework\ajax-methods.php:91
noprivwp_ajax_vayapin_checkout_fillframework\ajax-methods.php:92
authwp_ajax_vayapin_checkout_fillframework\ajax-methods.php:96
noprivwp_ajax_vayapin_checkout_fillframework\ajax-methods.php:97
authwp_ajax_vayapin_save_to_orderframework\ajax-methods.php:137
noprivwp_ajax_vayapin_save_to_orderframework\ajax-methods.php:138
WordPress Hooks 19
actionadmin_menuframework\backend-ui\admin-ui.php:18
actionadmin_initframework\backend-ui\admin-ui.php:95
actionwoocommerce_checkout_before_customer_detailsframework\frontend-ui\checkout-ui.php:62
filterplugin_action_links_vayapin-woocommerce/vayapin-woocommerce.phpframework\settings.php:17
actionwp_enqueue_scriptsframework\styles-scripts\styles-scripts.php:64
actionadmin_enqueue_scriptsframework\styles-scripts\styles-scripts.php:65
actionwoocommerce_thankyouframework\styles-scripts\styles-scripts.php:93
filterwoocommerce_order_actionsframework\woocommerce\generate-label.php:17
actionwoocommerce_order_action_print_vayapin_labelframework\woocommerce\generate-label.php:27
actionwoocommerce_admin_order_data_after_shipping_addressframework\woocommerce\generate-label.php:65
filterquery_varsframework\woocommerce\generate-label.php:73
actioninitframework\woocommerce\generate-label.php:80
actiontemplate_redirectframework\woocommerce\generate-label.php:98
actionwp_enqueue_scriptsframework\woocommerce\vayapin-label-template.php:67
actionplugins_loadedincludes\class-vayapin.php:142
actionadmin_enqueue_scriptsincludes\class-vayapin.php:157
actionadmin_enqueue_scriptsincludes\class-vayapin.php:158
actionwp_enqueue_scriptsincludes\class-vayapin.php:173
actionwp_enqueue_scriptsincludes\class-vayapin.php:174
Maintenance & Trust

VayaPin Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJun 19, 2026
PHP min version7.4
Downloads808

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

VayaPin Connector Developer Profile

vayapin

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VayaPin Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vayapin/admin/css/vayapin-admin.css/wp-content/plugins/vayapin/admin/js/vayapin-admin.js/wp-content/plugins/vayapin/public/css/countrySelect.css/wp-content/plugins/vayapin/public/js/countrySelect.js/wp-content/plugins/vayapin/public/css/vendor/select2.min.css/wp-content/plugins/vayapin/public/js/vendor/select2.min.js/wp-content/plugins/vayapin/public/js/vayapin-select2.js/wp-content/plugins/vayapin/public/js/vayapin-checkout.js
Version Parameters
vayapin-admin.css?ver=vayapin-admin.js?ver=countrySelect.css?ver=countrySelect.js?ver=select2.min.css?ver=select2.min.js?ver=vayapin-select2.js?ver=vayapin-checkout.js?ver=

HTML / DOM Fingerprints

JS Globals
vayapinSelect2vayapinCheckout
FAQ

Frequently Asked Questions about VayaPin Connector