Yakkyofy Security & Risk Analysis

wordpress.org/plugins/yakkyofy

Yakkyofy completely automates your woocommerce dropshipping store so you can focus on what matters most: marketing. You run ads, we power your store.

50 active installs v1.0.12 PHP 7.0+ WP 5.2+ Updated Jan 22, 2025
dropshippingecommercefulfillmentproduct-sourcingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yakkyofy Safe to Use in 2026?

Generally Safe

Score 92/100

Yakkyofy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "yakkyofy" v1.0.12 plugin exhibits a generally strong security posture based on the provided static analysis. It has a minimal attack surface with no unprotected entry points and utilizes prepared statements for all SQL queries, which is a significant strength. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, there are areas for improvement. The plugin only performs one capability check, and there are no nonce checks implemented, which could be a concern if the REST API endpoints were to become more complex or handle sensitive operations. Additionally, while the plugin has no known vulnerabilities in its history, the lack of taint analysis and incomplete output escaping (58% properly escaped) indicates that there could be undiscovered vulnerabilities, particularly around how data is handled and presented to the user. The plugin's security history is clean, suggesting a diligent development process or a lack of targeting, but it's crucial to maintain this vigilance and address the identified code-level weaknesses.

Key Concerns

  • No nonce checks implemented
  • Output escaping is only 58% proper
  • Only one capability check performed
Vulnerabilities
None known

Yakkyofy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yakkyofy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

58% escaped12 total outputs
Attack Surface

Yakkyofy Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

GET/wp-json/wc/v3/yakkyofy/fulfillmentintegrations\Yakkyofy.php:108
GET/wp-json/wc/v3/yakkyofy/healthintegrations\Yakkyofy.php:136
WordPress Hooks 10
actionwpmu_new_blogbackend\ActDeact.php:32
actionadmin_bar_menubackend\Admin_Area.php:48
actionadmin_enqueue_scriptsbackend\Enqueue.php:33
actionadmin_enqueue_scriptsbackend\Enqueue.php:34
actionrest_api_initintegrations\Yakkyofy.php:43
actionrest_api_initintegrations\Yakkyofy.php:44
actionadmin_inityakkyofy.php:60
actionadmin_noticesyakkyofy.php:66
actionbefore_woocommerce_inityakkyofy.php:83
actionplugins_loadedyakkyofy.php:112
Maintenance & Trust

Yakkyofy Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 22, 2025
PHP min version7.0
Downloads11K

Community Trust

Rating98/100
Number of ratings63
Active installs50
Developer Profile

Yakkyofy Developer Profile

Yakkyofy

1 plugin · 50 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yakkyofy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yakkyofy/assets/css/settings.css/wp-content/plugins/yakkyofy/assets/js/settings.js
Script Paths
/wp-content/plugins/yakkyofy/assets/js/settings.js
Version Parameters
yakkyofy-settings-styles?ver=yakkyofy-settings-script?ver=

HTML / DOM Fingerprints

JS Globals
yakkyofy_request
REST Endpoints
/wc/v3/yakkyofy/fulfillment/wc/v3/yakkyofy/health
FAQ

Frequently Asked Questions about Yakkyofy