Advanced Woo Ajax Search Security & Risk Analysis

wordpress.org/plugins/advanced-woo-ajax-search

Most advanced woo ajax search plugin for WooCommerce

0 active installs v1.0.1 PHP 7.3+ WP 6.1+ Updated Oct 10, 2023
ajax-searchproduct-searchwoo-searchwoocommercewoocommerce-search
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Woo Ajax Search Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Woo Ajax Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'advanced-woo-ajax-search' plugin v1.0.1 presents a mixed security posture. On the positive side, it shows no history of known vulnerabilities (CVEs) and employs prepared statements for all its SQL queries, which is a strong security practice against SQL injection. Furthermore, the absence of file operations and external HTTP requests reduces the potential for certain attack vectors. The taint analysis also indicates no critical or high severity unsanitized paths.

However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, opening them up to abuse. While the code analysis doesn't reveal dangerous functions or specific exploitable flows from taint analysis, the lack of authentication on these entry points is a critical oversight. The plugin also bundles Select2, and while the data doesn't specify its version or if it's outdated, bundled libraries can sometimes introduce vulnerabilities if not maintained.

In conclusion, while the plugin demonstrates good practices in data handling (SQL prepared statements) and has a clean vulnerability history, the absence of authorization checks on its AJAX endpoints is a major security weakness. This makes it susceptible to unauthorized actions or information disclosure. The plugin's strengths in SQL handling and lack of past CVEs are overshadowed by its exposed attack surface.

Key Concerns

  • AJAX handlers without auth checks
  • Bundled library (Select2) - potential risk if outdated
Vulnerabilities
None known

Advanced Woo Ajax Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced Woo Ajax Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
11
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared4 total queries

Output Escaping

76% escaped46 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
advanced_woo_product_title (includes\functions.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Advanced Woo Ajax Search Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_awas_woo_search_product_title_actionincludes\functions.php:38
noprivwp_ajax_awas_woo_search_product_title_actionincludes\functions.php:39
WordPress Hooks 13
actiondelete_widgetadmin\class-advanced-awas-woo-admin.php:17
actionadmin_initadmin\class-advanced-awas-woo-admin.php:19
actionadmin_menuadmin\class-advanced-awas-woo-admin.php:20
actionadmin_noticesadvanced-woo-ajax-search.php:95
actionplugins_loadedadvanced-woo-ajax-search.php:99
actionwidgets_initincludes\class-advanced-awas-woo-widget.php:8
actionwp_headincludes\class-advanced-awas-woo.php:135
actionplugins_loadedincludes\class-advanced-awas-woo.php:152
actionadmin_enqueue_scriptsincludes\class-advanced-awas-woo.php:167
actionadmin_enqueue_scriptsincludes\class-advanced-awas-woo.php:168
actionwp_enqueue_scriptsincludes\class-advanced-awas-woo.php:191
actionwp_enqueue_scriptsincludes\class-advanced-awas-woo.php:192
actionwidgets_initincludes\class-advanced-woo-search-widget.php:8
Maintenance & Trust

Advanced Woo Ajax Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 10, 2023
PHP min version7.3
Downloads997

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Advanced Woo Ajax Search Developer Profile

Farid Mia

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Woo Ajax Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-woo-ajax-search/public/css/advanced-woo-ajax-search.css/wp-content/plugins/advanced-woo-ajax-search/public/js/advanced-woo-ajax-search.js
Script Paths
/wp-content/plugins/advanced-woo-ajax-search/public/js/advanced-woo-ajax-search.js
Version Parameters
advanced-woo-ajax-search/public/css/advanced-woo-ajax-search.css?ver=advanced-woo-ajax-search/public/js/advanced-woo-ajax-search.js?ver=

HTML / DOM Fingerprints

CSS Classes
awas-woo-search-formawas-woo-search-field
Data Attributes
data-awas_woo_nonce
JS Globals
AWAS_WOO_OBJECT
REST Endpoints
/wp-json/awas-woo/v1/search
FAQ

Frequently Asked Questions about Advanced Woo Ajax Search