
Custom Shop Filter by Webnotics Security & Risk Analysis
wordpress.org/plugins/custom-shop-filter-by-webnoticsAn advanced product filtering plugin for WooCommerce, allowing users to filter products by taxonomy and custom field.
Is Custom Shop Filter by Webnotics Safe to Use in 2026?
Generally Safe
Score 100/100Custom Shop Filter by Webnotics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-shop-filter-by-webnotics v1.0.1 plugin demonstrates several positive security practices, including the absence of dangerous functions, file operations, and external HTTP requests. Crucially, all SQL queries are performed using prepared statements, which significantly mitigates the risk of SQL injection vulnerabilities. The presence of numerous nonce checks (11) indicates an effort to protect against CSRF attacks. Furthermore, the plugin has a clean vulnerability history with no known CVEs, suggesting a generally well-maintained codebase.
However, there are areas for improvement. The static analysis reveals that 25% of the 442 output operations are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. Additionally, while all entry points are accounted for, the lack of explicit capability checks on any of the AJAX handlers is a concern. This means that theoretically, any authenticated user could trigger these AJAX actions, which might not be the intended behavior and could lead to privilege escalation or unintended data manipulation if the AJAX actions themselves have sensitive functionalities. The absence of any recorded historical vulnerabilities is positive, but it does not negate the potential risks identified in the current code analysis.
In conclusion, the plugin has a solid foundation with its SQL query handling and lack of known historical vulnerabilities. The primary areas of concern are the unescaped output and the absence of capability checks on AJAX handlers. Addressing these would significantly strengthen the plugin's security posture.
Key Concerns
- Unescaped output (25% of 442)
- No capability checks on AJAX handlers
Custom Shop Filter by Webnotics Security Vulnerabilities
Custom Shop Filter by Webnotics Release Timeline
Custom Shop Filter by Webnotics Code Analysis
Output Escaping
Data Flow Analysis
Custom Shop Filter by Webnotics Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Custom Shop Filter by Webnotics Maintenance & Trust
Maintenance Signals
Community Trust
Custom Shop Filter by Webnotics Alternatives
RND Product Filters with ajax for WooCommerce
rnd-wc-product-filters-with-ajax
Woocommerce Ajax Product Filter with that when you install this plugin that will auto change and load the product wihtout loading or refreshing the pa …
FiboSearch – Ajax Search for WooCommerce
ajax-search-for-woocommerce
The most popular WooCommerce product search plugin. Gives your users a well-designed advanced AJAX search bar with live search suggestions.
HUSKY – Products Filter Professional for WooCommerce
woocommerce-products-filter
HUSKY - WooCommerce Products Filter Professional (former name is WOOF) – flexible, easy and robust professional filter for products for WooCommerce
YITH WooCommerce Ajax Product Filter
yith-woocommerce-ajax-navigation
YITH WooCommerce Ajax Product Filter offers you the perfect way to filter all products of your WooCommerce shop.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Custom Shop Filter by Webnotics Developer Profile
3 plugins · 50 total installs
How We Detect Custom Shop Filter by Webnotics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-shop-filter-by-webnotics/assets/css/style.css/wp-content/plugins/custom-shop-filter-by-webnotics/assets/fontawesome/css/all.min.css/wp-content/plugins/custom-shop-filter-by-webnotics/assets/css/bootstrap-min-css.css/wp-content/plugins/custom-shop-filter-by-webnotics/assets/js/custom.js/wp-content/plugins/custom-shop-filter-by-webnotics/assets/js/admin.js/wp-content/plugins/custom-shop-filter-by-webnotics/assets/js/custom.js/wp-content/plugins/custom-shop-filter-by-webnotics/assets/js/admin.jscustom-shop-filter-by-webnotics/assets/css/style.css?ver=custom-shop-filter-by-webnotics/assets/fontawesome/css/all.min.css?ver=custom-shop-filter-by-webnotics/assets/css/bootstrap-min-css.css?ver=custom-shop-filter-by-webnotics/assets/js/custom.js?ver=custom-shop-filter-by-webnotics/assets/js/admin.js?ver=HTML / DOM Fingerprints
csfbw-admin-noticecsfbw-custom-filterdata-nonceajax_object