Yoycol Integration for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yoycol-print-on-demand

Grow your store with the top print-on-demand dropshipping plugin

400 active installs v1.2.5 PHP 5.6+ WP 4.9+ Updated Jun 8, 2023
drop-shippingshippingshipping-rateswoocommerceyoycol
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yoycol Integration for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Yoycol Integration for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'yoycol-print-on-demand' plugin version 1.2.5 exhibits a generally positive security posture based on the provided static analysis. The absence of detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the code signals show no dangerous functions and all SQL queries are secured with prepared statements, which are excellent practices for preventing common vulnerabilities. The lack of file operations and external HTTP requests also reduces potential exposure. However, the static analysis reveals a critical concern regarding output escaping. With one total output detected and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data outputted by the plugin that is not properly escaped can be manipulated by attackers to inject malicious scripts, which could lead to session hijacking, defacement, or other harmful actions.

The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. This suggests that historically, the plugin has not been a significant target or has been maintained with security in mind. The lack of any recorded vulnerabilities, common types, or recent issues further reinforces this observation. The absence of any identified taint flows also suggests that the plugin is not exhibiting complex data handling issues that could lead to severe vulnerabilities like SQL injection or path traversal. Despite the clean history and limited attack surface, the significant flaw in output escaping poses a direct and present risk that needs immediate attention. The overall security is good in terms of attack surface and data handling, but the lack of output escaping is a major weakness.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Yoycol Integration for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yoycol Integration for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Yoycol Integration for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptsincludes\admin.php:17
actionadmin_menuincludes\admin.php:18
actionrest_api_initincludes\admin.php:19
Maintenance & Trust

Yoycol Integration for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 8, 2023
PHP min version5.6
Downloads7K

Community Trust

Rating70/100
Number of ratings4
Active installs400
Developer Profile

Yoycol Integration for WooCommerce Developer Profile

Yoycol

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yoycol Integration for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yoycol-print-on-demand/build/static/js//wp-content/plugins/yoycol-print-on-demand/build/static/css/
Script Paths
wp-content/plugins/yoycol-print-on-demand/build/static/js/

HTML / DOM Fingerprints

JS Globals
window.yoycolStoreData
REST Endpoints
/wp-json/yoycol/v1/set_access_key/wp-json/yoycol/v1/clear_all/wp-json/yoycol/v1/set_access_token/wp-json/yoycol/v1/clear_all_token
Shortcode Output
<div id='yoycol-root'>
FAQ

Frequently Asked Questions about Yoycol Integration for WooCommerce