
Yandex pay Security & Risk Analysis
wordpress.org/plugins/yandex-payОфициальный модуль Yandex Pay
Is Yandex pay Safe to Use in 2026?
Generally Safe
Score 85/100Yandex pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yandex-pay" plugin version 1.1.4 exhibits a mixed security posture. On the positive side, there are no recorded historical vulnerabilities, no dangerous functions used, and all SQL queries are properly prepared, indicating good practices in database interaction. Output escaping is generally well-implemented, with over 90% of outputs being properly handled. However, several concerns arise from the static analysis. The absence of nonce checks and capability checks on any potential entry points is a significant weakness, especially considering the plugin makes 11 external HTTP requests. While the attack surface is reported as zero, this could be misleading if not all potential entry points were analyzed or if vulnerabilities exist within the external requests themselves. The taint analysis reveals two high-severity flows with unsanitized paths, which represent a tangible risk. These unsanitized paths could lead to potential injection vulnerabilities if external data is not handled with extreme care before being used in sensitive operations, particularly in conjunction with the external HTTP requests.
Key Concerns
- High severity taint flows with unsanitized paths
- No nonce checks on any entry points
- No capability checks on any entry points
- Significant number of external HTTP requests
- Some output escaping issues identified
Yandex pay Security Vulnerabilities
Yandex pay Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Yandex pay Attack Surface
WordPress Hooks 17
Maintenance & Trust
Yandex pay Maintenance & Trust
Maintenance Signals
Community Trust
Yandex pay Alternatives
Billingotomatis – Tren Otomatisasi Indonesia
billingotomatis-payment-gateway-indonesia
Billingotomatis merupakan layanan yang bisa membuat bisnis Anda menjadi otomatis, menghemat waktu, dan menambah prestise bisnis Anda.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
Yandex pay Developer Profile
3 plugins · 600 total installs
How We Detect Yandex pay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yandex-pay/assets/js/one-click-checkout.js/wp-content/plugins/yandex-pay/assets/js/one-click-checkout.jsyandex-pay/style.css?ver=woocommerce_yandex_pay_one_click_checkout?ver=HTML / DOM Fingerprints
yandex-pay-buttondata-yandex-pay-buttonyandex_pay_checkout_params/wp-json/yandexpay/v1/add-to-cart/wp-json/yandexpay/v1/shipping