Яндекс Доставка Security & Risk Analysis

wordpress.org/plugins/yandex-go-delivery

Яндекс Доставка — это сервис, который помогает бизнесам отправлять заказы клиентам внутри города и между городами.

300 active installs v1.13 PHP 7.4+ WP 6.0.0+ Updated Oct 11, 2024
deliveryshipmentshippingshipping-methodwoocommerce-shipping
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Яндекс Доставка Safe to Use in 2026?

Generally Safe

Score 92/100

Яндекс Доставка has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'yandex-go-delivery' v1.13 exhibits a generally positive security posture based on the provided static analysis. A notable strength is the complete absence of identified CVEs, indicating a history of stable and likely well-maintained code. The static analysis reveals no dangerous functions, critical or high severity taint flows, or SQL queries that are not prepared, all of which are excellent indicators of secure coding practices.

However, there are significant areas for concern. The most glaring issue is the complete lack of any nonce checks or capability checks. This means that any functionality exposed by the plugin, even if it's not directly through AJAX or REST APIs, could potentially be triggered by any authenticated user, regardless of their role or intended permissions. The low percentage of properly escaped output is also a significant risk, as it leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Any data processed or displayed by the plugin that is not properly escaped could be manipulated by an attacker to inject malicious scripts.

In conclusion, while the plugin avoids common critical vulnerabilities like unpatched CVEs and insecure SQL queries, its failure to implement fundamental security checks like nonces and capability checks, coupled with a high rate of unescaped output, presents a substantial risk of Cross-Site Scripting and privilege escalation. The absence of any attack surface in the reported metrics is a positive sign, but it doesn't negate the inherent risks introduced by poor output sanitization and lack of authorization checks on its internal operations.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • Low output escaping percentage
Vulnerabilities
None known

Яндекс Доставка Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Яндекс Доставка Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
340
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
2
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

100% prepared1 total queries

Output Escaping

12% escaped388 total outputs
Attack Surface

Яндекс Доставка Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_menuincludes\WC_Yandex_Taxi_Admin_Menu.php:16
actionadmin_noticesincludes\WC_Yandex_Taxi_Delivery_Admin_Error.php:19
actionwoocommerce_shipping_initincludes\WC_Yandex_Taxi_Delivery_App.php:80
filterwoocommerce_shipping_methodsincludes\WC_Yandex_Taxi_Delivery_App.php:81
filterwoocommerce_payment_gatewaysincludes\WC_Yandex_Taxi_Delivery_App.php:84
filterwoocommerce_payment_gatewaysincludes\WC_Yandex_Taxi_Delivery_App.php:88
filterwoocommerce_order_data_store_cpt_get_orders_queryincludes\WC_Yandex_Taxi_Delivery_App.php:94
actionget_new_events_hookincludes\WC_Yandex_Taxi_Delivery_App.php:98
filterwoocommerce_admin_order_actionsincludes\WC_Yandex_Taxi_Delivery_App.php:100
actionadmin_headincludes\WC_Yandex_Taxi_Delivery_App.php:106
filtercron_schedulesincludes\WC_Yandex_Taxi_Delivery_App.php:109
actionadd_meta_boxesincludes\WC_Yandex_Taxi_Delivery_App.php:112
filteryandex_go/post_payment_methodsincludes\WC_Yandex_Taxi_Delivery_Payment_Method.php:31
filterwoocommerce_available_payment_gatewaysincludes\WC_Yandex_Taxi_Delivery_Shipping_Controller.php:15
actionwoocommerce_after_shipping_rateincludes\WC_Yandex_Taxi_Delivery_Shipping_Controller.php:17
filterwoocommerce_cart_shipping_method_full_labelincludes\WC_Yandex_Taxi_Delivery_Shipping_Method.php:51
actionbefore_woocommerce_inityandex-go-delivery.php:44
actionadmin_noticesyandex-go-delivery.php:63
actionnetwork_admin_noticesyandex-go-delivery.php:64
Maintenance & Trust

Яндекс Доставка Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 11, 2024
PHP min version7.4
Downloads9K

Community Trust

Rating28/100
Number of ratings7
Active installs300
Developer Profile

Яндекс Доставка Developer Profile

Yandex Delivery

1 plugin · 300 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Яндекс Доставка

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yandex-go-delivery/assets/lib/jquery-ui/jquery-ui.css/wp-content/plugins/yandex-go-delivery/assets/lib/intlTelInput/js/intlTelInput-jquery.min.js/wp-content/plugins/yandex-go-delivery/assets/lib/intlTelInput/css/intlTelInput.min.css/wp-content/plugins/yandex-go-delivery/assets/js/gmap.js/wp-content/plugins/yandex-go-delivery/assets/js/map.js/wp-content/plugins/yandex-go-delivery/assets/js/validation.js/wp-content/plugins/yandex-go-delivery/assets/js/create-claim.js
Script Paths
https://maps.googleapis.com/maps/api/js?key=https://api-maps.yandex.ru/2.1/?lang=
Version Parameters
yandex-go-delivery/assets/lib/jquery-ui/jquery-ui.css?ver=yandex-go-delivery/assets/lib/intlTelInput/js/intlTelInput-jquery.min.js?ver=yandex-go-delivery/assets/lib/intlTelInput/css/intlTelInput.min.css?ver=yandex-go-delivery/assets/js/gmap.js?ver=yandex-go-delivery/assets/js/map.js?ver=yandex-go-delivery/assets/js/validation.js?ver=yandex-go-delivery/assets/js/create-claim.js?ver=

HTML / DOM Fingerprints

CSS Classes
yandex-taxi-delivery_claim_formyandex-taxi-delivery_formyandex-taxi-delivery_settings_gridyandex-taxi-delivery_form__route_pointyandex-taxi-delivery_setting_form__groupyandex-taxi-delivery_form__route_headingyandex-taxi-delivery_form__titleyandex-taxi-delivery_form__row+9 more
HTML Comments
defined( 'ABSPATH' ) || exit;
Data Attributes
id="yandex-taxi-delivery_claim_form"name="warehouse[address]"name="warehouse[coordinate]"class="js_yandex-taxi-delivery_form__param js_yandex-taxi-delivery_form__param_address"class="js_yandex-taxi-delivery_form__param js_yandex-taxi-delivery_form__param_coordinate"class="js_yandex-taxi-delivery_form__param"
JS Globals
yandexSettings
REST Endpoints
/wp-json/yandex-go-delivery/confirm
FAQ

Frequently Asked Questions about Яндекс Доставка