Ajax loader + Cache Security & Risk Analysis

wordpress.org/plugins/ajax-loader-cache

Ajax loading + built-in cache for WordPress, compatible with other cache plugins like WP-Rocket لودینگ ایجکسی + کش داخلی برای وردپرس، سازگار با دیگر ا …

100 active installs v1.6.41 PHP 7.3+ WP + Updated Nov 12, 2025
ajaxajax-loadloadloading
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ajax loader + Cache Safe to Use in 2026?

Generally Safe

Score 100/100

Ajax loader + Cache has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The ajax-loader-cache plugin v1.6.41 demonstrates a mixed security posture. On the positive side, the plugin has no known CVEs, indicating a history of responsible development or minimal past security issues. The static analysis also shows no direct SQL injection vulnerabilities and a single file operation that isn't flagged as problematic. However, there are significant areas for improvement. A notable concern is the low percentage of properly escaped output (47%), which suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the total attack surface is small and the single AJAX handler has a capability check, the low output escaping rate means any data processed and displayed could be manipulated by attackers. The presence of a flow with unsanitized paths, even without a critical or high severity rating, warrants attention as it could potentially lead to path traversal or other file-related exploits if exploited in conjunction with other weaknesses. The lack of nonce checks on the AJAX handler, despite a capability check being present, is a common oversight that can lead to Cross-Site Request Forgery (CSRF) attacks.

Key Concerns

  • Low percentage of properly escaped output
  • Flow with unsanitized paths detected
  • Missing nonce check on AJAX handler
Vulnerabilities
None known

Ajax loader + Cache Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ajax loader + Cache Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
353
319 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped672 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<settings-pagehtml> (admin\settings-pagehtml.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ajax loader + Cache Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpjsloadbymdz_emptyOptions_AjaxConfadmin\admin-ajax.php:98
WordPress Hooks 10
actionadmin_menuadmin\class-admin.php:33
actionadmin_footeradmin\class-admin.php:68
actionadmin_footeradmin\class-admin.php:89
actioninitajax-loader-bymdez.php:58
actionwp_headajax-loader-bymdez.php:517
actionwp_enqueue_scriptsajax-loader-bymdez.php:559
actionwp_footerajax-loader-bymdez.php:564
actiontemplate_redirectajax-loader-bymdez.php:859
actionwp_headajax-loader-bymdez.php:863
actionwp_enqueue_scriptsajax-loader-bymdez.php:904
Maintenance & Trust

Ajax loader + Cache Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.3
Downloads71K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Ajax loader + Cache Developer Profile

MDZ

4 plugins · 730 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Ajax loader + Cache

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ajax-loader-cache/assets/css/loader.css/wp-content/plugins/ajax-loader-cache/assets/js/loader.js/wp-content/plugins/ajax-loader-cache/assets/js/lazyload.js
Script Paths
/wp-content/plugins/ajax-loader-cache/assets/js/loader.js/wp-content/plugins/ajax-loader-cache/assets/js/lazyload.js
Version Parameters
ajax-loader-cache/assets/css/loader.css?ver=ajax-loader-cache/assets/js/loader.js?ver=ajax-loader-cache/assets/js/lazyload.js?ver=

HTML / DOM Fingerprints

JS Globals
wpjsloadbymdz_def_settingswpjsloadbymdz_normalize_urlwpjsloadbymdz_addsettingsbtnwpjsloadbymdz_i18n
FAQ

Frequently Asked Questions about Ajax loader + Cache