Yedpay for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yedpay-for-woocommerce

Easily accept Alipay, AlipayHK, Wechat Pay, UnionPay, Visa and mastercard on your Wordpress site using Yedpay WooCommerce payment gateway in one plugi …

300 active installs v1.2.3 PHP + WP 3.0.1+ Updated Jul 9, 2025
alipayalipayhkunionpayvisawechat-pay
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yedpay for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Yedpay for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'yedpay-for-woocommerce' plugin v1.2.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals a clean codebase with no identified dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are prepared, and output escaping is almost entirely correctly implemented, significantly reducing the risk of common vulnerabilities like SQL injection and XSS. The absence of any reported CVEs, including critical or high severity ones, further reinforces the impression of a well-maintained and secure plugin.

However, the analysis does highlight a complete absence of capability checks and nonce checks across all potential entry points, which are reported as zero. While the current attack surface appears negligible (0 AJAX handlers, 0 REST API routes, etc.), this is a significant concern. If future updates or developer oversight introduce even a single unprotected entry point, it could lead to severe vulnerabilities. The plugin's strength lies in its current clean state, but its weakness lies in the lack of foundational security mechanisms that would protect it should its attack surface grow.

In conclusion, 'yedpay-for-woocommerce' v1.2.3 is currently a very secure plugin with no known vulnerabilities and a codebase that follows many good security practices. The lack of vulnerability history is a positive indicator. The primary weakness is the complete reliance on the absence of an attack surface rather than implementing robust security checks like capability and nonce checks, which are standard best practices for any WordPress plugin.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Minor unescaped output (2%)
Vulnerabilities
None known

Yedpay for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yedpay for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
41 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped42 total outputs
Attack Surface

Yedpay for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionbefore_woocommerce_initindex.php:23
actionplugins_loadedindex.php:37
filterwoocommerce_payment_gatewaysindex.php:59
actionwoocommerce_update_options_payment_gatewaysWoocommerceYedpay.php:62
actioninitWoocommerceYedpay.php:69
actionwoocommerce_initWoocommerceYedpay.php:70
actionwoocommerce_api_woocommerceyedpayWoocommerceYedpay.php:72
Maintenance & Trust

Yedpay for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 9, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Yedpay for WooCommerce Developer Profile

yedpay

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yedpay for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yedpay-for-woocommerce/assets/css/yedpay-custom.css/wp-content/plugins/yedpay-for-woocommerce/assets/js/yedpay-custom.js/wp-content/plugins/yedpay-for-woocommerce/assets/images/yedpay.svg
Script Paths
assets/js/yedpay-custom.js
Version Parameters
yedpay-for-woocommerce/assets/css/yedpay-custom.css?ver=yedpay-for-woocommerce/assets/js/yedpay-custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
yedpay-gateway-logo
Data Attributes
data-yedpay-gateway-logo
REST Endpoints
woocommerceyedpay
FAQ

Frequently Asked Questions about Yedpay for WooCommerce