
YEWS Optimisations Security & Risk Analysis
wordpress.org/plugins/yews-optimisationsYEWS Optimisations for the websites that are using the Modernize, Flawless and Total Business themes from Goodlayers.
Is YEWS Optimisations Safe to Use in 2026?
Generally Safe
Score 85/100YEWS Optimisations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yews-optimisations" plugin v4.6.2.2 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and no identified critical or high-severity taint flows, which are significant indicators of a generally well-maintained and secure codebase. The absence of dangerous functions, file operations, and external HTTP requests also contributes to a reduced attack surface. However, there are notable concerns arising from the static code analysis. The plugin performs SQL queries without utilizing prepared statements, which is a direct pathway to SQL injection vulnerabilities if the input is not meticulously sanitized elsewhere. Additionally, a substantial portion of the plugin's output is not properly escaped, creating a risk of Cross-Site Scripting (XSS) attacks. The lack of nonce checks on its single entry point (shortcode) is also a concern for potential Cross-Site Request Forgery (CSRF) attacks, though the absence of AJAX and REST API endpoints mitigates this specific risk somewhat. The plugin's vulnerability history is strong, but the static analysis reveals potential weaknesses that could be exploited if not addressed.
Key Concerns
- Raw SQL queries without prepared statements
- Unescaped output detected
- Missing nonce checks on entry points
YEWS Optimisations Security Vulnerabilities
YEWS Optimisations Code Analysis
SQL Query Safety
Output Escaping
YEWS Optimisations Attack Surface
Shortcodes 1
WordPress Hooks 29
Scheduled Events 1
Maintenance & Trust
YEWS Optimisations Maintenance & Trust
Maintenance Signals
Community Trust
YEWS Optimisations Alternatives
No alternatives data available yet.
YEWS Optimisations Developer Profile
2 plugins · 60 total installs
How We Detect YEWS Optimisations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yews-optimisations/include/yews/custom-login.css/wp-content/plugins/yews-optimisations/include/yews/custom-footer.css/wp-content/plugins/yews-optimisations/include/yews/custom-yews-page.css/wp-content/plugins/yews-optimisations/include/yews/custom-micro-structured-data.css/wp-content/plugins/yews-optimisations/include/yews/custom-enquiries.css/wp-content/plugins/yews-optimisations/include/yews/custom-options.css/wp-content/plugins/yews-optimisations/include/yews/custom-checks.css/wp-content/plugins/yews-optimisations/js/custom-login.js+6 more/wp-content/plugins/yews-optimisations/js/custom-login.js/wp-content/plugins/yews-optimisations/js/custom-footer.js/wp-content/plugins/yews-optimisations/js/custom-yews-page.js/wp-content/plugins/yews-optimisations/js/custom-micro-structured-data.js/wp-content/plugins/yews-optimisations/js/custom-enquiries.js/wp-content/plugins/yews-optimisations/js/custom-options.js+1 moreyews-optimisations/include/yews/custom-login.css?ver=yews-optimisations/include/yews/custom-footer.css?ver=yews-optimisations/include/yews/custom-yews-page.css?ver=yews-optimisations/include/yews/custom-micro-structured-data.css?ver=yews-optimisations/include/yews/custom-enquiries.css?ver=yews-optimisations/include/yews/custom-options.css?ver=yews-optimisations/include/yews/custom-checks.css?ver=yews-optimisations/js/custom-login.js?ver=yews-optimisations/js/custom-footer.js?ver=yews-optimisations/js/custom-yews-page.js?ver=yews-optimisations/js/custom-micro-structured-data.js?ver=yews-optimisations/js/custom-enquiries.js?ver=yews-optimisations/js/custom-options.js?ver=yews-optimisations/js/custom-checks.js?ver=HTML / DOM Fingerprints
yews-hello-bardata-hellobar-textdata-hellobar-button-textdata-hellobar-button-urldata-hellobar-classesdata-hellobar-bg-colordata-hellobar-text-coloryews_hellobar_textyews_hellobar_button_textyews_hellobar_button_urlyews_hellobar_classesyews_hellobar_bg_coloryews_hellobar_text_color