Ajax loader + Cache Security & Risk Analysis

wordpress.org/plugins/ajax-loader-cache

Ajax loading + built-in cache for WordPress, compatible with other cache plugins like WP-Rocket لودینگ ایجکسی + کش داخلی برای وردپرس، سازگار با دیگر ا …

100 active installs v1.6.41 PHP 7.3+ WP + Updated Nov 12, 2025
ajaxajax-loadloadloading
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ajax loader + Cache Safe to Use in 2026?

Generally Safe

Score 100/100

Ajax loader + Cache has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The ajax-loader-cache plugin v1.6.41 demonstrates a mixed security posture. On the positive side, the plugin has no known CVEs, indicating a history of responsible development or minimal past security issues. The static analysis also shows no direct SQL injection vulnerabilities and a single file operation that isn't flagged as problematic. However, there are significant areas for improvement. A notable concern is the low percentage of properly escaped output (47%), which suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the total attack surface is small and the single AJAX handler has a capability check, the low output escaping rate means any data processed and displayed could be manipulated by attackers. The presence of a flow with unsanitized paths, even without a critical or high severity rating, warrants attention as it could potentially lead to path traversal or other file-related exploits if exploited in conjunction with other weaknesses. The lack of nonce checks on the AJAX handler, despite a capability check being present, is a common oversight that can lead to Cross-Site Request Forgery (CSRF) attacks.

Key Concerns

  • Low percentage of properly escaped output
  • Flow with unsanitized paths detected
  • Missing nonce check on AJAX handler
Vulnerabilities
None known

Ajax loader + Cache Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ajax loader + Cache Release Timeline

v1.6.41Current
v1.6.40
v1.6.36
v1.6.35
v1.6.31
v1.6.30
v1.6.20
v1.6.15
v1.6.00
v1.5.55
v1.5.01
v1.5.00
v1.4.55
v1.4.27
v1.4.25
v1.4.08
v1.4.06
v1.4.05
v1.4.00
v1.3.85
Code Analysis
Analyzed Mar 16, 2026

Ajax loader + Cache Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
353
319 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped672 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<settings-pagehtml> (admin\settings-pagehtml.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ajax loader + Cache Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpjsloadbymdz_emptyOptions_AjaxConfadmin\admin-ajax.php:98
WordPress Hooks 10
actionadmin_menuadmin\class-admin.php:33
actionadmin_footeradmin\class-admin.php:68
actionadmin_footeradmin\class-admin.php:89
actioninitajax-loader-bymdez.php:58
actionwp_headajax-loader-bymdez.php:517
actionwp_enqueue_scriptsajax-loader-bymdez.php:559
actionwp_footerajax-loader-bymdez.php:564
actiontemplate_redirectajax-loader-bymdez.php:859
actionwp_headajax-loader-bymdez.php:863
actionwp_enqueue_scriptsajax-loader-bymdez.php:904
Maintenance & Trust

Ajax loader + Cache Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.3
Downloads71K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Ajax loader + Cache Developer Profile

MDZ

4 plugins · 740 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Ajax loader + Cache

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ajax-loader-cache/assets/css/loader.css/wp-content/plugins/ajax-loader-cache/assets/js/loader.js/wp-content/plugins/ajax-loader-cache/assets/js/lazyload.js
Script Paths
/wp-content/plugins/ajax-loader-cache/assets/js/loader.js/wp-content/plugins/ajax-loader-cache/assets/js/lazyload.js
Version Parameters
ajax-loader-cache/assets/css/loader.css?ver=ajax-loader-cache/assets/js/loader.js?ver=ajax-loader-cache/assets/js/lazyload.js?ver=

HTML / DOM Fingerprints

JS Globals
wpjsloadbymdz_def_settingswpjsloadbymdz_normalize_urlwpjsloadbymdz_addsettingsbtnwpjsloadbymdz_i18n
FAQ

Frequently Asked Questions about Ajax loader + Cache