
Post Grid Master — Post Grids & AJAX Filters Security & Risk Analysis
wordpress.org/plugins/ajax-filter-postsCreate post grids with AJAX filters, pagination, load more, infinite scroll, and custom post type support.
Is Post Grid Master — Post Grids & AJAX Filters Safe to Use in 2026?
Use With Caution
Score 62/100Post Grid Master — Post Grids & AJAX Filters has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "ajax-filter-posts" plugin exhibits a mixed security posture. While the static analysis shows a commendable effort with 80% of SQL queries using prepared statements and 85% of outputs being properly escaped, significant concerns remain. The presence of 7 known CVEs, with one still unpatched and classified as critical, is a major red flag. This history includes severe vulnerability types like XSS, missing authorization, PHP Remote File Inclusion, and Path Traversal, indicating a recurring pattern of insecure input handling and access control issues in past versions. The taint analysis revealing two flows with unsanitized paths, although not reaching critical or high severity in this specific scan, are potential precursors to the types of vulnerabilities seen in its history, especially when combined with past findings of "Improper Control of Filename for Include/Require Statement" and "Path Traversal". The plugin's attack surface, though currently showing no unprotected entry points, has historically been a source of significant risk.
Key Concerns
- Unpatched critical CVE
- Multiple historical vulnerability types
- Flows with unsanitized paths (2)
- 80% SQL prepared, 20% may not be
- 85% output escaped, 15% may not be
Post Grid Master — Post Grids & AJAX Filters Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Post Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text']
Post Grid Master <= 3.4.14 - Missing Authorization
Post Grid Master <= 3.4.12 - Authenticated (Contributor+) Local File Inclusion
Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion
Post Grid Master <= 3.4.10 - Reflected Cross-Site Scripting
Post Grid Master <= 3.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Post Grid Master <= 3.4.7 - Missing Authorization
Post Grid Master — Post Grids & AJAX Filters Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Grid Master — Post Grids & AJAX Filters Attack Surface
AJAX Handlers 3
Shortcodes 3
WordPress Hooks 24
Maintenance & Trust
Post Grid Master — Post Grids & AJAX Filters Maintenance & Trust
Maintenance Signals
Community Trust
Post Grid Master — Post Grids & AJAX Filters Alternatives
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
ultimate-post
A highly customizable plugin to create news, magazines, and any kind of blog site with post grid, post filter, post slider, and post blocks.
Load More Products for WooCommerce
load-more-products-for-woocommerce
Load products from next page via AJAX with infinite scrolling or load more products button
YITH Infinite Scrolling
yith-infinite-scrolling
Add infinite scrolling to archive post or shop page.
Load More Anything
ajax-load-more-anything
Add Load More button for your blog post, custom type, Comments, page, Category, Recent Posts, Woocommerce Product, custom Div or whatever you want.
Category AJAX Filter – Advanced Filter for Posts & Custom Post Types
category-ajax-filter
Filter WordPress posts and custom post types by categories, tags, and taxonomies with AJAX-powered filtering — no page reload required.
Post Grid Master — Post Grids & AJAX Filters Developer Profile
10 plugins · 7K total installs
How We Detect Post Grid Master — Post Grids & AJAX Filters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-filter-posts/assets/frontend.min.js/wp-content/plugins/ajax-filter-posts/assets/css/frontend.min.css/wp-content/plugins/ajax-filter-posts/assets/frontend.min.jsajax-filter-posts/assets/frontend.min.js?ver=ajax-filter-posts/assets/css/frontend.min.css?ver=HTML / DOM Fingerprints
data-gridmaster-idasr_ajax_params