
ЮKassa для WooCommerce Security & Risk Analysis
wordpress.org/plugins/yookassaПрием платежей на сайтах WooCommerce. Разработка и поддержка — компания ЮMoney
Is ЮKassa для WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100ЮKassa для WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The Yookassa plugin v2.15.0 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and the absence of bundled libraries, significant concerns arise from its attack surface and output sanitization. The presence of four AJAX handlers without authentication checks is a major vulnerability, opening the door for unauthorized actions. Furthermore, the low percentage of properly escaped output suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Past vulnerabilities: High severity
- Past vulnerabilities: Medium severity
ЮKassa для WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ЮKassa для WooCommerce <= 2.3.0 - Cross-Site Request Forgery to Settings Update
ЮKassa для WooCommerce <= 2.3.0 - Missing Authorization
ЮKassa для WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ЮKassa для WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
ЮKassa для WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ЮKassa для WooCommerce Alternatives
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
ЮKassa для WooCommerce Developer Profile
1 plugin · 9K total installs
How We Detect ЮKassa для WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yookassa/admin/css/bootstrap-datetimepicker.min.css/wp-content/plugins/yookassa/admin/css/bootstrap.min.css/wp-content/plugins/yookassa/admin/css/colorbox.css/wp-content/plugins/yookassa/admin/css/jquery-ui.css/wp-content/plugins/yookassa/admin/css/yookassa_admin.css/wp-content/plugins/yookassa/admin/js/bootstrap-datetimepicker.min.js/wp-content/plugins/yookassa/admin/js/bootstrap.min.js/wp-content/plugins/yookassa/admin/js/bootstrap.bundle.min.js+5 more/wp-content/plugins/yookassa/admin/js/bootstrap-datetimepicker.min.js/wp-content/plugins/yookassa/admin/js/bootstrap.min.js/wp-content/plugins/yookassa/admin/js/bootstrap.bundle.min.js/wp-content/plugins/yookassa/admin/js/jquery.colorbox-min.js/wp-content/plugins/yookassa/admin/js/jquery-ui.js/wp-content/plugins/yookassa/admin/js/yookassa_admin.js+1 moreyookassa/admin/css/bootstrap-datetimepicker.min.css?ver=yookassa/admin/css/bootstrap.min.css?ver=yookassa/admin/css/colorbox.css?ver=yookassa/admin/css/jquery-ui.css?ver=yookassa/admin/css/yookassa_admin.css?ver=yookassa/admin/js/bootstrap-datetimepicker.min.js?ver=yookassa/admin/js/bootstrap.min.js?ver=yookassa/admin/js/bootstrap.bundle.min.js?ver=yookassa/admin/js/jquery.colorbox-min.js?ver=yookassa/admin/js/jquery-ui.js?ver=yookassa/admin/js/yookassa_admin.js?ver=yookassa/assets/css/yookassa-checkout.css?ver=yookassa/assets/js/yookassa-checkout.js?ver=HTML / DOM Fingerprints
yookassa_wrapyookassa_titleyookassa_inputyookassa_button<!-- BEGIN YM payment.template --><!-- END YM payment.template --><!-- YOOkassa.IO START --><!-- YOOkassa.IO END -->data-yookassa-payment-gatewaydata-yookassa-order-idYooKassaCheckoutYooKassa/wp-json/yookassa/v1/order/capture/wp-json/yookassa/v1/order/refund[yookassa_payment_button]