
Яндекс Доставка Security & Risk Analysis
wordpress.org/plugins/yandex-go-deliveryЯндекс Доставка — это сервис, который помогает бизнесам отправлять заказы клиентам внутри города и между городами.
Is Яндекс Доставка Safe to Use in 2026?
Generally Safe
Score 92/100Яндекс Доставка has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'yandex-go-delivery' v1.13 exhibits a generally positive security posture based on the provided static analysis. A notable strength is the complete absence of identified CVEs, indicating a history of stable and likely well-maintained code. The static analysis reveals no dangerous functions, critical or high severity taint flows, or SQL queries that are not prepared, all of which are excellent indicators of secure coding practices.
However, there are significant areas for concern. The most glaring issue is the complete lack of any nonce checks or capability checks. This means that any functionality exposed by the plugin, even if it's not directly through AJAX or REST APIs, could potentially be triggered by any authenticated user, regardless of their role or intended permissions. The low percentage of properly escaped output is also a significant risk, as it leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Any data processed or displayed by the plugin that is not properly escaped could be manipulated by an attacker to inject malicious scripts.
In conclusion, while the plugin avoids common critical vulnerabilities like unpatched CVEs and insecure SQL queries, its failure to implement fundamental security checks like nonces and capability checks, coupled with a high rate of unescaped output, presents a substantial risk of Cross-Site Scripting and privilege escalation. The absence of any attack surface in the reported metrics is a positive sign, but it doesn't negate the inherent risks introduced by poor output sanitization and lack of authorization checks on its internal operations.
Key Concerns
- No nonce checks detected
- No capability checks detected
- Low output escaping percentage
Яндекс Доставка Security Vulnerabilities
Яндекс Доставка Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Яндекс Доставка Attack Surface
WordPress Hooks 19
Maintenance & Trust
Яндекс Доставка Maintenance & Trust
Maintenance Signals
Community Trust
Яндекс Доставка Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Štíteknabalík.cz
foxdeli
Looking for a reliable label printing solution? Štíteknabalík.cz will help you!
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
bpost shipping
bpost-shipping
This plugin allows customers to choose their preferred Belgian bpost delivery method when ordering in your Woocommerce webshop.
User role based shipping methods
user-role-based-shipping-method
Display WooCommerce shipping methods based on User Role and Country. Globally compatible.
Яндекс Доставка Developer Profile
1 plugin · 300 total installs
How We Detect Яндекс Доставка
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yandex-go-delivery/assets/lib/jquery-ui/jquery-ui.css/wp-content/plugins/yandex-go-delivery/assets/lib/intlTelInput/js/intlTelInput-jquery.min.js/wp-content/plugins/yandex-go-delivery/assets/lib/intlTelInput/css/intlTelInput.min.css/wp-content/plugins/yandex-go-delivery/assets/js/gmap.js/wp-content/plugins/yandex-go-delivery/assets/js/map.js/wp-content/plugins/yandex-go-delivery/assets/js/validation.js/wp-content/plugins/yandex-go-delivery/assets/js/create-claim.jshttps://maps.googleapis.com/maps/api/js?key=https://api-maps.yandex.ru/2.1/?lang=yandex-go-delivery/assets/lib/jquery-ui/jquery-ui.css?ver=yandex-go-delivery/assets/lib/intlTelInput/js/intlTelInput-jquery.min.js?ver=yandex-go-delivery/assets/lib/intlTelInput/css/intlTelInput.min.css?ver=yandex-go-delivery/assets/js/gmap.js?ver=yandex-go-delivery/assets/js/map.js?ver=yandex-go-delivery/assets/js/validation.js?ver=yandex-go-delivery/assets/js/create-claim.js?ver=HTML / DOM Fingerprints
yandex-taxi-delivery_claim_formyandex-taxi-delivery_formyandex-taxi-delivery_settings_gridyandex-taxi-delivery_form__route_pointyandex-taxi-delivery_setting_form__groupyandex-taxi-delivery_form__route_headingyandex-taxi-delivery_form__titleyandex-taxi-delivery_form__row+9 moredefined( 'ABSPATH' ) || exit;id="yandex-taxi-delivery_claim_form"name="warehouse[address]"name="warehouse[coordinate]"class="js_yandex-taxi-delivery_form__param js_yandex-taxi-delivery_form__param_address"class="js_yandex-taxi-delivery_form__param js_yandex-taxi-delivery_form__param_coordinate"class="js_yandex-taxi-delivery_form__param"yandexSettings/wp-json/yandex-go-delivery/confirm