
WooYD Security & Risk Analysis
wordpress.org/plugins/wooydYandex Delivery (https://delivery.yandex.ru) and WooCommerce - sync, integration, connection
Is WooYD Safe to Use in 2026?
Generally Safe
Score 85/100WooYD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wooyd" v0.8.2 plugin presents a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no recorded vulnerabilities or CVEs, significant concerns arise from its output escaping and lack of security checks. The static analysis reveals that 100% of its outputs are not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce and capability checks on its entry points (shortcodes) means that any user, regardless of their privileges, could potentially trigger actions related to these shortcodes, which could be exploited if the shortcode's functionality is sensitive or can be manipulated. The taint analysis showing no flows is positive, but the lack of output escaping and security checks on entry points negates much of this benefit. The vulnerability history showing zero CVEs is a positive indicator, suggesting the plugin has historically been secure, but this does not mitigate the present risks identified in the code analysis. In conclusion, the plugin has a clean history and avoids certain risky coding practices, but the severe lack of output escaping and insufficient security checks on its entry points represent critical vulnerabilities that need immediate attention.
Key Concerns
- All outputs unescaped
- No nonce checks on entry points
- No capability checks on entry points
WooYD Security Vulnerabilities
WooYD Code Analysis
Output Escaping
WooYD Attack Surface
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
WooYD Maintenance & Trust
Maintenance Signals
Community Trust
WooYD Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
WooMS
wooms
MoySklad (moysklad.ru) and WooCommerce - sync, integration, connection
Data Sync for Xero by Wbsync
data-sync-x-by-wbsync
Automatically sync your data, like orders and inventory, from WooCommerce to Xero.
WooAmoConnector
wooamoconnector
amoCRM (https://www.amocrm.com/) and WooCommerce - sync, integration, connection
W2S Sync – WooCommerce to Shopify Sync
w2s-sync
Sync WooCommerce and Shopify products, orders, and customers with real-time and bidirectional sync with our WooCommerce to Shopify Sync Plugin.
WooYD Developer Profile
7 plugins · 700 total installs
How We Detect WooYD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wooyd/assets/css/cart-widget.css/wp-content/plugins/wooyd/assets/js/cart-widget.js/wp-content/plugins/wooyd/inc/class-wc-shipping-yandex-delivery.php/wp-content/plugins/wooyd/inc/class-settings.php/wp-content/plugins/wooyd/inc/cart-widget.php/wp-content/plugins/wooyd/inc/class-widget-track.php/wp-content/plugins/wooyd/inc/class-widget-info.php/wp-content/plugins/wooyd/inc/class-widget-geo.php+1 morewooyd/assets/css/cart-widget.css?ver=wooyd/assets/js/cart-widget.js?ver=HTML / DOM Fingerprints
yd-select-variants<!-- Создаем условный объект с данными о содержимом корзины (для примера) --><!-- Инициализация виджета -->data-ydwidget-openwindow.cartydwidget<input type="hidden" name="yd_cost"<input type="hidden" name="yd_params"<div><a href="#yd-select-variants" data-ydwidget-open>Выбрать варианты</a></div>