
AGP Ajax Taxonomy Filter Security & Risk Analysis
wordpress.org/plugins/agp-ajax-taxonomy-filterSimple Ajax Taxonomy Filter
Is AGP Ajax Taxonomy Filter Safe to Use in 2026?
Generally Safe
Score 85/100AGP Ajax Taxonomy Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'agp-ajax-taxonomy-filter' plugin version 1.1.0 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs and correctly uses prepared statements for all its SQL queries, which is a strong indicator of good database security practices. Furthermore, all identified AJAX handlers and REST API routes appear to have appropriate permission checks in place, and there are no file operations or cron events that could present common attack vectors.
However, the static analysis reveals several areas of concern. The presence of the `unserialize` function, a known source of potential vulnerabilities when handling untrusted input, is a significant red flag. This is further exacerbated by the taint analysis, which identified two high-severity flows with unsanitized paths. While the number of these flows is relatively low, their high severity combined with the use of `unserialize` suggests a tangible risk of code execution or data manipulation if an attacker can control the input to these functions. Additionally, a notable portion (60%) of output escaping is missing, which could lead to Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and good practices in SQL handling and access control for its entry points, the identified high-severity taint flows coupled with the use of `unserialize` and insufficient output escaping represent critical areas that require immediate attention. The plugin has strengths in its structured approach to handling data and access, but these specific weaknesses could be exploited.
Key Concerns
- High severity taint flows detected
- Dangerous function 'unserialize' used
- Insufficient output escaping (40% escaped)
- Unsanitized paths in taint flows
AGP Ajax Taxonomy Filter Security Vulnerabilities
AGP Ajax Taxonomy Filter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AGP Ajax Taxonomy Filter Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
AGP Ajax Taxonomy Filter Maintenance & Trust
Maintenance Signals
Community Trust
AGP Ajax Taxonomy Filter Alternatives
Category AJAX Filter – Advanced Filter for Posts & Custom Post Types
category-ajax-filter
Filter WordPress posts and custom post types by categories, tags, and taxonomies with AJAX-powered filtering — no page reload required.
Search & Filter
search-filter
Search and Filtering for Custom Posts, Categories, Tags, Taxonomies, Post Dates and Post Types
Advanced AJAX Product Filters
woocommerce-ajax-filters
Fast and flexible AJAX product filters for WooCommerce. Filter by categories, attributes, price, tags, rating, and more. No page reloads.
Post Grid Master — Post Grids & AJAX Filters
ajax-filter-posts
Create post grids with AJAX filters, pagination, load more, infinite scroll, and custom post type support.
GA Admin Taxonomy Search
ga-admin-taxonomy-search
Make it easy to search/filter items in your admin categories meta box.
AGP Ajax Taxonomy Filter Developer Profile
1 plugin · 20 total installs
How We Detect AGP Ajax Taxonomy Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/js/main.js/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/css/style.css/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/js/admin.js/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/css/admin.css/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/js/main.js/wp-content/plugins/agp-ajax-taxonomy-filter/agp-core/classes/fields/repeater/js/admin.jsHTML / DOM Fingerprints
agp-repeater-containerCopyright Alexey GolubnichenkoThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+2 moreagp-repeater-containerAtf