YEWS Optimisations Security & Risk Analysis

wordpress.org/plugins/yews-optimisations

YEWS Optimisations for the websites that are using the Modernize, Flawless and Total Business themes from Goodlayers.

50 active installs v4.6.2.2 PHP + WP + Updated Oct 5, 2016
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YEWS Optimisations Safe to Use in 2026?

Generally Safe

Score 85/100

YEWS Optimisations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "yews-optimisations" plugin v4.6.2.2 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and no identified critical or high-severity taint flows, which are significant indicators of a generally well-maintained and secure codebase. The absence of dangerous functions, file operations, and external HTTP requests also contributes to a reduced attack surface. However, there are notable concerns arising from the static code analysis. The plugin performs SQL queries without utilizing prepared statements, which is a direct pathway to SQL injection vulnerabilities if the input is not meticulously sanitized elsewhere. Additionally, a substantial portion of the plugin's output is not properly escaped, creating a risk of Cross-Site Scripting (XSS) attacks. The lack of nonce checks on its single entry point (shortcode) is also a concern for potential Cross-Site Request Forgery (CSRF) attacks, though the absence of AJAX and REST API endpoints mitigates this specific risk somewhat. The plugin's vulnerability history is strong, but the static analysis reveals potential weaknesses that could be exploited if not addressed.

Key Concerns

  • Raw SQL queries without prepared statements
  • Unescaped output detected
  • Missing nonce checks on entry points
Vulnerabilities
None known

YEWS Optimisations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YEWS Optimisations Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
30
0 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped30 total outputs
Attack Surface

YEWS Optimisations Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[yews-optimisations] include\yews\custom-yews-page.php:40
WordPress Hooks 29
filteryews_menu_iteminclude\yews\custom-checks.php:9
filteryews_menu_pagesinclude\yews\custom-checks.php:39
actionyews_daily_checksinclude\yews\custom-checks.php:42
actioninitinclude\yews\custom-checks.php:110
filterauto_update_plugininclude\yews\custom-checks.php:147
actionyews_daily_checksinclude\yews\custom-checks.php:150
actionyews_daily_checksinclude\yews\custom-checks.php:205
filteryews_menu_iteminclude\yews\custom-enquiries.php:7
filteryews_menu_pagesinclude\yews\custom-enquiries.php:68
actionwp_footerinclude\yews\custom-footer.php:65
actionlogin_headinclude\yews\custom-login.php:50
filterlogin_headerurlinclude\yews\custom-login.php:55
filterlogin_headertitleinclude\yews\custom-login.php:60
filterlogin_messageinclude\yews\custom-login.php:68
filteryews_menu_iteminclude\yews\custom-micro-structured-data.php:7
filteryews_menu_pagesinclude\yews\custom-micro-structured-data.php:42
actionwp_headinclude\yews\custom-micro-structured-data.php:79
actioncustomize_registerinclude\yews\custom-options.php:469
actionwp_headinclude\yews\custom-options.php:472
actionwp_headinclude\yews\custom-options.php:490
actionwp_headinclude\yews\custom-options.php:527
actionwp_footerinclude\yews\custom-options.php:633
actionwp_footerinclude\yews\custom-options.php:646
actionwp_footerinclude\yews\custom-options.php:665
actionwp_enqueue_scriptsinclude\yews\custom-options.php:684
actionwp_footerinclude\yews\custom-options.php:686
actioninitinclude\yews\custom-yews-page.php:42
actionadmin_menuinclude\yews\custom-yews-page.php:74
actionadmin_initinclude\yews\custom-yews-page.php:75

Scheduled Events 1

yews_daily_checks
Maintenance & Trust

YEWS Optimisations Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 5, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Alternatives

YEWS Optimisations Alternatives

No alternatives data available yet.

Developer Profile

YEWS Optimisations Developer Profile

Grigory Metlenko

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YEWS Optimisations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yews-optimisations/include/yews/custom-login.css/wp-content/plugins/yews-optimisations/include/yews/custom-footer.css/wp-content/plugins/yews-optimisations/include/yews/custom-yews-page.css/wp-content/plugins/yews-optimisations/include/yews/custom-micro-structured-data.css/wp-content/plugins/yews-optimisations/include/yews/custom-enquiries.css/wp-content/plugins/yews-optimisations/include/yews/custom-options.css/wp-content/plugins/yews-optimisations/include/yews/custom-checks.css/wp-content/plugins/yews-optimisations/js/custom-login.js+6 more
Script Paths
/wp-content/plugins/yews-optimisations/js/custom-login.js/wp-content/plugins/yews-optimisations/js/custom-footer.js/wp-content/plugins/yews-optimisations/js/custom-yews-page.js/wp-content/plugins/yews-optimisations/js/custom-micro-structured-data.js/wp-content/plugins/yews-optimisations/js/custom-enquiries.js/wp-content/plugins/yews-optimisations/js/custom-options.js+1 more
Version Parameters
yews-optimisations/include/yews/custom-login.css?ver=yews-optimisations/include/yews/custom-footer.css?ver=yews-optimisations/include/yews/custom-yews-page.css?ver=yews-optimisations/include/yews/custom-micro-structured-data.css?ver=yews-optimisations/include/yews/custom-enquiries.css?ver=yews-optimisations/include/yews/custom-options.css?ver=yews-optimisations/include/yews/custom-checks.css?ver=yews-optimisations/js/custom-login.js?ver=yews-optimisations/js/custom-footer.js?ver=yews-optimisations/js/custom-yews-page.js?ver=yews-optimisations/js/custom-micro-structured-data.js?ver=yews-optimisations/js/custom-enquiries.js?ver=yews-optimisations/js/custom-options.js?ver=yews-optimisations/js/custom-checks.js?ver=

HTML / DOM Fingerprints

CSS Classes
yews-hello-bar
Data Attributes
data-hellobar-textdata-hellobar-button-textdata-hellobar-button-urldata-hellobar-classesdata-hellobar-bg-colordata-hellobar-text-color
JS Globals
yews_hellobar_textyews_hellobar_button_textyews_hellobar_button_urlyews_hellobar_classesyews_hellobar_bg_coloryews_hellobar_text_color
FAQ

Frequently Asked Questions about YEWS Optimisations