
Live Data Display Security & Risk Analysis
wordpress.org/plugins/auto-refresh-api-ajaxLoad JSON data via API, display it on your WordPress site, and auto-refresh it at custom intervals — without reloading the page.
Is Live Data Display Safe to Use in 2026?
Generally Safe
Score 100/100Live Data Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-refresh-api-ajax" plugin v1.2.10 presents a significant security risk due to a lack of proper authentication and authorization checks on its entry points. All identified AJAX handlers and REST API routes are exposed without any validation, meaning any user, regardless of their role or permissions, could potentially interact with these functions. While the plugin demonstrates good practices in other areas, such as using prepared statements for SQL queries and largely escaping output, this single area of weakness can lead to serious vulnerabilities if exploited. The absence of any recorded historical vulnerabilities might suggest that the exposed entry points have not been widely targeted or exploited in the past, but this does not mitigate the current risk. The overall security posture is concerning, leaning towards insecure due to the critical gap in access control.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
- Total entry points without auth
Live Data Display Security Vulnerabilities
Live Data Display Release Timeline
Live Data Display Code Analysis
Output Escaping
Data Flow Analysis
Live Data Display Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
Live Data Display Maintenance & Trust
Maintenance Signals
Community Trust
Live Data Display Alternatives
Disable REST API
disable-json-api
Disable the use of the REST API on your website to site users. Now with User Role support!
Heartbeat Control
heartbeat-control
Allows you to easily manage the frequency of the WordPress heartbeat API.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
Disable WP REST API
disable-wp-rest-api
Disables the WP REST API for visitors not logged into WordPress.
WordPress REST API (Version 2)
rest-api
Access your site's data through an easy-to-use HTTP REST API. (Version 2)
Live Data Display Developer Profile
5 plugins · 17K total installs
How We Detect Live Data Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-refresh-api-ajax/js/auto_refresh_api_ajax.js/wp-content/plugins/auto-refresh-api-ajax/js/auto_refresh_api_ajax.jsauto-refresh-api-ajax/js/auto_refresh_api_ajax.js?ver=auto-refresh-api-ajax.js?ver=HTML / DOM Fingerprints
autorefreshapiajaxparam/wp-json/araa/v1/geturl/