Load More Anything Security & Risk Analysis

wordpress.org/plugins/ajax-load-more-anything

Add Load More button for your blog post, custom type, Comments, page, Category, Recent Posts, Woocommerce Product, custom Div or whatever you want.

6K active installs v3.3.9 PHP 5.6+ WP 4.6+ Updated Nov 19, 2025
ajaxajax-load-moreajax-paginationinfinite-scrollload-more
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2024
Safety Verdict

Is Load More Anything Safe to Use in 2026?

Generally Safe

Score 100/100

Load More Anything has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 31, 2024Updated 4mo ago
Risk Assessment

The "ajax-load-more-anything" plugin v3.3.9 demonstrates a generally good security posture with several positive indicators. The absence of critical or high severity taint flows, a complete lack of raw SQL queries, and a high percentage of properly escaped output are commendable practices. The presence of multiple nonce and capability checks on its entry points, coupled with no detected unprotected AJAX handlers or REST API routes, suggests an effort to secure its attack surface. The plugin also does not bundle any external libraries, which avoids the risks associated with outdated or vulnerable third-party code.

However, the plugin's vulnerability history presents a notable concern. A medium severity vulnerability was recorded relatively recently in January 2024, and it was noted as a 'Missing Authorization' type. While currently patched, this history indicates a recurring pattern that warrants attention. The fact that this was the only known CVE, and it's now patched, does temper the concern slightly, but it highlights an area where diligent review and testing are crucial.

In conclusion, while the current version exhibits strong defensive coding practices and a secure attack surface, the past medium severity authorization vulnerability requires ongoing vigilance. Users should ensure they are always on the latest version and be aware of the plugin's history. The plugin's strengths lie in its secure coding practices for the current version, but its past vulnerability suggests a potential for authorization flaws to be introduced or overlooked.

Key Concerns

  • Medium severity vulnerability history
  • Recent medium severity vulnerability (2024-01-31)
Vulnerabilities
1

Load More Anything Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-24704medium · 5.4Missing Authorization

Load More Anything <= 3.3.3 - Missing Authorization to Plugin Settings Modification

Jan 31, 2024 Patched in 3.3.4 (8d)
Code Analysis
Analyzed Mar 16, 2026

Load More Anything Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
41
342 escaped
Nonce Checks
7
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

89% escaped383 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ald_save_option_ajax_function (admin\functions.php:147)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Load More Anything Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_ald_save_settingsadmin\functions.php:146
authwp_ajax_ald_add_general_loadmoreadmin\functions.php:173
authwp_ajax_ald_add_ajax_loadmoreadmin\functions.php:477
WordPress Hooks 23
actionupdate_option_ald_optionsadmin\functions.php:143
actionald_left_paneladmin\functions.php:823
actionadmin_footeradmin\functions.php:987
actionald_options_jsadmin\functions.php:1051
actionadmin_menuadmin\Menu.php:12
actionald_general_loadmore_after_wrapadmin\Menu.php:13
actionald_ajax_loadmore_after_wrapadmin\Menu.php:14
filterald_before_options_saveadmin\Menu.php:16
actionplugins_loadedajax-load-div.php:35
actionwp_enqueue_scriptsajax-load-div.php:38
actionadmin_enqueue_scriptsajax-load-div.php:39
actionswitch_themeappsero\src\Insights.php:135
actionswitch_themeappsero\src\Insights.php:136
actionadmin_footerappsero\src\Insights.php:146
actionadmin_noticesappsero\src\Insights.php:161
actionadmin_initappsero\src\Insights.php:164
filtercron_schedulesappsero\src\Insights.php:168
actionadmin_menuappsero\src\License.php:219
actionafter_switch_themeappsero\src\License.php:781
actionswitch_themeappsero\src\License.php:782
actionwp_headinc\ald-functions.php:119
actionwp_footerinc\ald-functions.php:551
actionwp_footerinc\ald-functions.php:564
Maintenance & Trust

Load More Anything Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 19, 2025
PHP min version5.6
Downloads108K

Community Trust

Rating90/100
Number of ratings73
Active installs6K
Developer Profile

Load More Anything Developer Profile

Akhtarujjaman Shuvo

10 plugins · 7K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
117 days
View full developer profile
Detection Fingerprints

How We Detect Load More Anything

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ajax-load-more-anything/assets/styles.min.css/wp-content/plugins/ajax-load-more-anything/assets/scripts.js/wp-content/plugins/ajax-load-more-anything/assets/admin.min.css/wp-content/plugins/ajax-load-more-anything/assets/admin.min.js
Script Paths
/wp-content/plugins/ajax-load-more-anything/assets/scripts.js/wp-content/plugins/ajax-load-more-anything/assets/admin.min.js
Version Parameters
/wp-content/plugins/ajax-load-more-anything/assets/styles.min.css?ver=3.3.9/wp-content/plugins/ajax-load-more-anything/assets/scripts.js?ver=3.3.9/wp-content/plugins/ajax-load-more-anything/assets/admin.min.css?ver=3.3.9/wp-content/plugins/ajax-load-more-anything/assets/admin.min.js?ver=3.3.9

HTML / DOM Fingerprints

CSS Classes
ald-load-more
Data Attributes
data-ald-noncedata-ald-ajaxurldata-ald-pro
JS Globals
ald_paramsalda_paramsALD_PLUGIN_VERSIONALD_PLUGIN_URLALD_PLUGIN_ASSETS
FAQ

Frequently Asked Questions about Load More Anything