YML Turbo Pages for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yml-turbo-pages-for-woocommerce

Plugin generates the YML file necessary for Yandex services.

100 active installs v1.0 PHP + WP 4.1.0+ Updated Oct 13, 2019
turbopageswoo-commercewoocommerceyandexyml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is YML Turbo Pages for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

YML Turbo Pages for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "yml-turbo-pages-for-woocommerce" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. It has no known vulnerabilities (CVEs) and the code analysis shows promising signs such as 100% of SQL queries using prepared statements and the presence of a nonce check. The attack surface is notably small, with no exposed AJAX handlers, REST API routes, or shortcodes that lack authentication. However, a significant concern arises from the output escaping, where only 35% of outputs are properly escaped, leaving a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. Additionally, the plugin performs file operations, and without specific details on how these are handled, there's an inherent risk if they are not secured against arbitrary file access or manipulation. The lack of capability checks is also a weakness, as it implies that actions might not be properly restricted to authorized users, although the limited attack surface mitigates this risk somewhat in this specific version.

Key Concerns

  • Insufficient output escaping
  • File operations without detail
  • No capability checks
Vulnerabilities
None known

YML Turbo Pages for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YML Turbo Pages for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

35% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
generate_yml_file_for_tubo_pages (yml-export-for-turbo-pages.php:79)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YML Turbo Pages for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionupdate_yml_fileyml-export-for-turbo-pages.php:39
actionplugins_loadedyml-export-for-turbo-pages.php:52
actionadmin_menuyml-export-for-turbo-pages.php:59

Scheduled Events 1

update_yml_file
Maintenance & Trust

YML Turbo Pages for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 13, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

YML Turbo Pages for WooCommerce Developer Profile

Gleb

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YML Turbo Pages for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yml-turbo-pages-for-woocommerce/assets/css/style.css/wp-content/plugins/yml-turbo-pages-for-woocommerce/assets/js/script.js
Script Paths
/wp-content/plugins/yml-turbo-pages-for-woocommerce/assets/js/script.js
Version Parameters
yml-turbo-pages-for-woocommerce/assets/css/style.css?ver=yml-turbo-pages-for-woocommerce/assets/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- If plugin not activated - hide form -->
Data Attributes
id="woo_yml_wrap"class="wrap"id="store_name"name="store_name"id="company_name"name="company_name"+8 more
FAQ

Frequently Asked Questions about YML Turbo Pages for WooCommerce