Import Products to Yandex Security & Risk Analysis

wordpress.org/plugins/wc-import-yandex

Exports products from your online store to Yandex Market. Helps to increase sales.

20 active installs v0.5.2 PHP 7.4.0+ WP 5.9+ Updated Jan 30, 2026
exportimportproductswoocommerceyandex
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Import Products to Yandex Safe to Use in 2026?

Generally Safe

Score 100/100

Import Products to Yandex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "wc-import-yandex" plugin version 0.5.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded CVEs and the consistent use of prepared statements for SQL queries are significant strengths, indicating a mature development process that prioritizes core security practices. The plugin also demonstrates good output escaping habits, with a high percentage of outputs properly handled. Nonce and capability checks are present, further contributing to a secure foundation.

However, the analysis does reveal some areas for improvement. The presence of 6 flows with unsanitized paths, although not flagged as critical or high severity in taint analysis, warrants attention. This suggests potential risks if these paths are not correctly handled within the application's logic, especially concerning file operations which are also present in the code. The inclusion of bundled libraries like Select2, while potentially convenient, could introduce vulnerabilities if not actively maintained and updated.

Overall, the plugin appears to be developed with security in mind, evidenced by its clean vulnerability history and robust coding practices. The limited attack surface and lack of critical code signals are positive indicators. The primary concern lies in the unsanitized path flows, which, while not explicitly critical, represent a potential entry point for unexpected behavior or vulnerabilities. Continuous monitoring for new vulnerabilities and ensuring all bundled libraries are up-to-date are recommended steps for maintaining its security.

Key Concerns

  • Flows with unsanitized paths
  • Bundled library (Select2)
Vulnerabilities
None known

Import Products to Yandex Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Import Products to Yandex Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
135 escaped
Nonce Checks
4
Capability Checks
3
File Operations
2
External Requests
3
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

88% escaped153 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

12 flows6 with unsanitized paths
get_html_block_logs (classes\system\class-ip2y-debug-page.php:114)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Import Products to Yandex Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 41
actionparse_requestclasses\generation\class-ip2y-api.php:102
actionmy_admin_noticesclasses\system\class-ip2y-debug-page.php:398
actionmy_admin_noticesclasses\system\class-ip2y-debug-page.php:422
actionsave_postclasses\system\class-ip2y-interface-hocked.php:41
actionwoocommerce_product_duplicateclasses\system\class-ip2y-interface-hocked.php:42
filterwoocommerce_product_data_tabsclasses\system\class-ip2y-interface-hocked.php:46
actionwoocommerce_product_data_panelsclasses\system\class-ip2y-interface-hocked.php:47
filterip2y_f_save_if_emptyclasses\system\class-ip2y-interface-hocked.php:49
actionwoocommerce_product_options_general_product_dataclasses\system\class-ip2y-interface-hocked.php:51
actionwoocommerce_variation_optionsclasses\system\class-ip2y-interface-hocked.php:52
actionadmin_initclasses\system\class-ip2y.php:152
actionadmin_initclasses\system\class-ip2y.php:153
actionadmin_menuclasses\system\class-ip2y.php:156
actionadmin_enqueue_scriptsclasses\system\class-ip2y.php:157
actionip2y_cron_sborkiclasses\system\class-ip2y.php:159
actionip2y_cron_periodclasses\system\class-ip2y.php:160
filtercron_schedulesclasses\system\class-ip2y.php:161
filterplugin_action_linksclasses\system\class-ip2y.php:163
filterip2y_f_external_descriptionclasses\system\class-ip2y.php:165
filterip2y_f_simple_descriptionclasses\system\class-ip2y.php:166
filterip2y_f_variable_descriptionclasses\system\class-ip2y.php:167
actionadmin_noticesclasses\system\class-ip2y.php:199
actionadmin_noticesclasses\system\class-ip2y.php:226
actionip2y_activation_formsclasses\system\updates\class-ip2y-plugin-form-activate.php:112
actionip2y_before_support_projectclasses\system\updates\class-ip2y-plugin-form-activate.php:114
filterpre_site_transient_update_pluginsclasses\system\updates\class-ip2y-plugin-form-activate.php:263
filterpre_set_site_transient_update_pluginsclasses\system\updates\class-ip2y-plugin-upd.php:136
filterplugins_apiclasses\system\updates\class-ip2y-plugin-upd.php:138
filterupgrader_package_optionsclasses\system\updates\class-ip2y-plugin-upd.php:140
filterplugin_action_linksclasses\system\updates\class-ip2y-plugin-upd.php:141
actionadmin_print_footer_scriptscommon-libs\class-icpd-feedback-1-0-3.php:86
actionadmin_initcommon-libs\class-icpd-feedback-1-0-3.php:93
actionadmin_noticescommon-libs\class-icpd-feedback-1-0-3.php:94
filterwp_mail_content_typecommon-libs\class-icpd-feedback-1-0-3.php:279
actionadmin_print_footer_scriptscommon-libs\class-icpd-promo.php:146
actionadmin_noticescommon-libs\class-icpd-set-admin-notices.php:87
actionadmin_noticeswc-import-yandex.php:42
actionadmin_noticeswc-import-yandex.php:62
actionbefore_woocommerce_initwc-import-yandex.php:74
actionplugins_loadedwc-import-yandex.php:132
actionplugins_loadedwc-import-yandex.php:141

Scheduled Events 2

ip2y_cron_sborki
ip2y_cron_period
Maintenance & Trust

Import Products to Yandex Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version7.4.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Import Products to Yandex Developer Profile

icopydoc

14 plugins · 16K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect Import Products to Yandex

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-import-yandex/assets/css/admin-settings.css/wp-content/plugins/wc-import-yandex/assets/css/style.css/wp-content/plugins/wc-import-yandex/assets/js/admin-settings.js/wp-content/plugins/wc-import-yandex/assets/js/script.js
Script Paths
/wp-content/plugins/wc-import-yandex/assets/js/admin-settings.js/wp-content/plugins/wc-import-yandex/assets/js/script.js
Version Parameters
wc-import-yandex/assets/css/admin-settings.css?ver=wc-import-yandex/assets/css/style.css?ver=wc-import-yandex/assets/js/admin-settings.js?ver=wc-import-yandex/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ip2y-settings-page-wrapperip2y-settings-page-contentip2y-settings-sectionip2y-settings-fieldip2y-settings-labelip2y-settings-inputip2y-settings-textareaip2y-settings-select+2 more
HTML Comments
<!-- Import Products to Yandex --><!-- end Import Products to Yandex -->
Data Attributes
data-ip2y-setting-iddata-ip2y-group-id
JS Globals
window.ip2y_settings_paramsvar ip2y_settings_params
FAQ

Frequently Asked Questions about Import Products to Yandex