
YandexId Plugin Security & Risk Analysis
wordpress.org/plugins/yandexidInstant login with Yandex ID
Is YandexId Plugin Safe to Use in 2026?
Generally Safe
Score 92/100YandexId Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The YandexID v2.0 plugin demonstrates some good security practices, such as using prepared statements for all SQL queries and largely proper output escaping. However, significant concerns arise from its attack surface. Two AJAX handlers are exposed without authentication checks, creating potential entry points for malicious activity if they can be exploited. The absence of nonce checks on these AJAX handlers further exacerbates this risk, making them more susceptible to Cross-Site Request Forgery (CSRF) attacks.
The plugin has a clean vulnerability history with no known CVEs. This is a positive indicator, suggesting that the plugin has not historically been a significant target for severe exploits. However, the static analysis reveals a lack of fundamental security controls on critical entry points, which could lead to future vulnerabilities being introduced. The absence of capability checks and nonce checks on AJAX handlers are particularly worrying, as these are standard WordPress security mechanisms designed to prevent unauthorized actions.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and has a clean history, its unprotected AJAX endpoints represent a notable security weakness. The lack of essential checks on these entry points elevates the risk profile. Developers should prioritize implementing authentication and nonce checks on these handlers to mitigate potential exploitation.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- No capability checks found
YandexId Plugin Security Vulnerabilities
YandexId Plugin Code Analysis
SQL Query Safety
Output Escaping
YandexId Plugin Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
YandexId Plugin Maintenance & Trust
Maintenance Signals
Community Trust
YandexId Plugin Alternatives
Yandex.Metrica
wp-yandex-metrika
The free official Yandex.Metrica plugin for WordPress.
CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor
mihdan-index-now
Improve your WordPress SEO with instant search-engine indexing, SEO insights, and indexing status tracking.
RSS for Yandex Turbo
rss-for-yandex-turbo
Создание RSS-ленты для сервиса Яндекс.Турбо.
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
YaMaps for WordPress Plugin
yamaps
The plugin allows you to add Yandex Maps (Яндекс Карты) to pages of your site using a WordPress visual editor.
YandexId Plugin Developer Profile
3 plugins · 600 total installs
How We Detect YandexId Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yandexid/js/settings.js/wp-content/plugins/yandexid/css/style.csshttps://yastatic.net/s3/passport-sdk/autofill/v1/sdk-suggest-with-polyfills-latest.jsyandexid/js/settings.js?ver=yandexid/css/style.css?ver=HTML / DOM Fingerprints
yandexid-formyandexid-yandexid_app_client_idyandexid-yandexid_app_client_secretyandexid-yandexid_type_selectionyandexid-yandexid_role_new_user<!--
*
*
* Настройки плагина
*
-->data-actionwindow.yandexid_app_client_idwindow.yandexid_app_client_secretwindow.yandexid_role_new_userwindow.yandexid_type_selectionwindow.scope_login_default_phone_fieldwindow.scope_login_birthday_field+10 more/yandexid/oauth<div class="text">Яндекс ID можно добавить на любой этап воронки и там, где, нужна авторизация.<br>Например в корзину и на страницу с комментариями.</div><div class="text">Начиная с версии 2.0, для дальнейшей работы модуля вам необходимо зарегистрировать приложение самостоятельно по ссылке <a href="https://oauth.yandex.ru/">https://oauth.yandex.ru/</a><br>Указав данные вашего хоста (Suggest Hostname) и ссылку для редиректа (Redirect URI). Пример ссылки редиректа - https://domen.ru/yandexid/oauth<br>В настройках модуля укажите полученные ClientID и Client secret</div>