
Yext Plugin Security & Risk Analysis
wordpress.org/plugins/yextThe Yext plugin lets you sync your menus, product lists, social network posts, and other business content from Yext to your WordPress site.
Is Yext Plugin Safe to Use in 2026?
Use With Caution
Score 63/100Yext Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Yext plugin v1.1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and having no external HTTP requests. The static analysis also found no critical or high severity taint flows, which is reassuring.
However, significant concerns arise from the lack of output escaping for all observed outputs. This means that user-supplied data displayed on the frontend could be vulnerable to cross-site scripting (XSS) attacks. Additionally, the complete absence of nonce checks and capability checks, even though there are no direct unprotected AJAX handlers or REST API routes listed, is a notable weakness. This makes it harder to prevent unauthorized actions if other entry points were discovered or introduced.
The plugin's vulnerability history, which includes one medium severity CVE with missing authorization and is currently unpatched, further amplifies these concerns. This specific vulnerability type aligns with the observed lack of capability checks in the code. While the number of CVEs is low, the presence of an unpatched vulnerability, especially one related to authorization, warrants immediate attention. The overall conclusion is that while the plugin avoids some common pitfalls, the lack of output escaping and the unpatched authorization vulnerability represent significant security risks.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
- Unpatched CVE (Medium Severity)
Yext Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Yext <= 1.1.3 - Missing Authorization
Yext Plugin Code Analysis
Output Escaping
Data Flow Analysis
Yext Plugin Attack Surface
Shortcodes 6
WordPress Hooks 5
Maintenance & Trust
Yext Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Yext Plugin Alternatives
Express Shop for WooCommerce Product Table
express-shop
This one page shop for WooCommerce will display woocommerce product table for easy bulk order. Suitable for restaurant online ordering, food menu, wh …
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels
webappick-product-feed-for-woocommerce
Create WooCommerce product feeds for Google Shopping, Facebook, TikTok & 220+ channels. 2026 compliant. 6 formats. Trusted by 70,000+ stores.
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Iks Menu – WordPress Category Accordion Menu & FAQs
iks-menu
Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).
Yext Plugin Developer Profile
4 plugins · 880 total installs
How We Detect Yext Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yext/public/css/yext.css//ajax.googleapis.com/ajax/libs/jquery/1.12.4/jquery.min.jsHTML / DOM Fingerprints
<!--There was an error connecting to Yext's services.--><!--The widget you are trying to use is not valid. Please update your widget so that it is linked to a specific location.--><!--The widget you are trying to use is not valid. Please make sure you have the correct id and type in your shortcode.--><!--The widget you are trying to use cannot be found.-->+1 moreid="yext-widget-iframe"id="persist-token-form"id="yext-login-token"id="remove-token-form"window.invokeFormActionwindow.establishConnectionwindow.sendConnectionRequestwindow.requestConnectionIntervalwindow.receiveMessage/Serving/ShouldLog/Serving/ReceiveLogMessage/Serving/WordpressHtml[yext-posts[yext-productlist[yext-calendar[yext-bios