Yakit for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yakit

Yakit - Hassle-free international shipping

0 active installs v1.2.3 PHP + WP 3.0+ Updated Feb 14, 2018
ddpguaranteed-duties-and-taxesshippingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yakit for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Yakit for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The yakit v1.2.3 plugin exhibits a generally good security posture with a clean vulnerability history and no known CVEs. The static analysis shows a commendable lack of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and file operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events indicates a deliberately limited attack surface, which is a positive security practice. However, there are areas of concern. The low percentage of properly escaped output (33%) suggests a potential for cross-site scripting (XSS) vulnerabilities, especially given the presence of external HTTP requests. The taint analysis, while not revealing critical or high severity issues, did identify two flows with unsanitized paths, which, when combined with the output escaping issues and external requests, could be leveraged in certain scenarios. The complete absence of nonce checks and capability checks is also a significant weakness. While the current attack surface is minimal, any future expansion or interaction with user-supplied data without these fundamental security measures would pose a serious risk. The plugin also makes one external HTTP request, which, without proper validation and sanitization of the data sent or received, can be a vector for attacks. In conclusion, while the plugin is currently free from known vulnerabilities and employs some good practices like prepared statements, the lack of output escaping, absence of crucial authorization checks (nonces and capabilities), and unsanitized taint flows represent significant potential risks that should be addressed.

Key Concerns

  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
  • External HTTP requests present
Vulnerabilities
None known

Yakit for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Yakit for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Yakit for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
add_subtab_settings (yakit-shipping.php:310)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Yakit for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwoocommerce_shipping_inityakit-shipping.php:222
filterwoocommerce_shipping_methodsyakit-shipping.php:230
actionactivated_pluginyakit-shipping.php:252
actionwoocommerce_email_before_order_tableyakit-shipping.php:256
filterwoocommerce_get_sections_apiyakit-shipping.php:282
actionadmin_menuyakit-shipping.php:290
filterwoocommerce_get_settings_apiyakit-shipping.php:309
actionwoocommerce_review_order_before_cart_contentsyakit-shipping.php:390
actionwoocommerce_after_checkout_validationyakit-shipping.php:391
Maintenance & Trust

Yakit for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedFeb 14, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Yakit for WooCommerce Developer Profile

jaggi

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yakit for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yakit/assets/css/frontend.css/wp-content/plugins/yakit/assets/js/frontend.js
Script Paths
/wp-content/plugins/yakit/assets/js/frontend.js
Version Parameters
yakit/assets/css/frontend.css?ver=yakit/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Yakit for WooCommerce