FtlCommerce – Instant Product Search Security & Risk Analysis

wordpress.org/plugins/ftlcommerce-instant-product-search

Lightning-fast, client-side fuzzy search for WooCommerce products. Zero server delays, instant results, advanced filtering.

0 active installs v1.0.0 PHP 8.2+ WP 6.4+ Updated Feb 13, 2026
ajax-searchfuzzy-searchlive-searchproduct-searchwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FtlCommerce – Instant Product Search Safe to Use in 2026?

Generally Safe

Score 100/100

FtlCommerce – Instant Product Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "ftlcommerce-instant-product-search" version 1.0.0 exhibits a generally good security posture due to strong adherence to secure coding practices. The plugin utilizes prepared statements for all SQL queries and properly escapes nearly all output, which significantly mitigates common risks like SQL injection and cross-site scripting. The absence of dangerous functions, external HTTP requests, and recorded vulnerabilities in its history are also positive indicators.

However, a significant concern arises from the presence of one REST API route that lacks permission callbacks. This creates an unprotected entry point into the plugin, potentially allowing unauthorized users to access or manipulate data. While the taint analysis shows no critical or high severity flows, this unprotected REST API route represents a tangible risk that could be exploited if it performs sensitive operations.

In conclusion, the plugin demonstrates a strong foundation in secure development. The developer has clearly implemented good practices for SQL and output handling. The primary weakness lies in the unprotected REST API endpoint, which requires immediate attention. Addressing this single vulnerability would greatly enhance the plugin's overall security.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

FtlCommerce – Instant Product Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FtlCommerce – Instant Product Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
1
128 escaped
Nonce Checks
5
Capability Checks
5
File Operations
11
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared12 total queries

Output Escaping

99% escaped129 total outputs
Attack Surface
1 unprotected

FtlCommerce – Instant Product Search Attack Surface

Entry Points2
Unprotected1

REST API Routes 1

GET/wp-json/fuse-commerce/v1/indexapp\Hooks\ActionRestApi.php:15

Shortcodes 1

[ftlcommerce] app\Hooks\ActionShortcodes.php:11
WordPress Hooks 7
actionadmin_menuapp\Hooks\ActionAdminMenu.php:14
actionadmin_enqueue_scriptsapp\Hooks\ActionEnqueueScripts.php:12
actionwp_enqueue_scriptsapp\Hooks\ActionEnqueueScripts.php:13
actionrest_api_initapp\Hooks\ActionRestApi.php:11
actionadmin_initapp\Hooks\ActionSettings.php:11
filtercron_schedulesapp\Hooks\FilterCronSchedules.php:12
actionfp_fscommerce_loadedftlcommerce-instant-product-search.php:22
Maintenance & Trust

FtlCommerce – Instant Product Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version8.2
Downloads123

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FtlCommerce – Instant Product Search Developer Profile

sakurapixel

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FtlCommerce – Instant Product Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ftlcommerce-instant-product-search/assets/admin/fuse-settings/dist/index.js/wp-content/plugins/ftlcommerce-instant-product-search/assets/admin/fuse-settings/dist/index.css/wp-content/plugins/ftlcommerce-instant-product-search/assets/vendor/toastr/toastr.min.js/wp-content/plugins/ftlcommerce-instant-product-search/assets/frontend/fuse-search/dist/index.js/wp-content/plugins/ftlcommerce-instant-product-search/assets/frontend/fuse-search/dist/index.css
Script Paths
assets/admin/fuse-settings/dist/index.jsassets/vendor/toastr/toastr.min.jsassets/frontend/fuse-search/dist/index.js
Version Parameters
/assets/admin/fuse-settings/dist/index.js?ver=v1/assets/admin/fuse-settings/dist/index.css?ver=v1/assets/frontend/fuse-search/dist/index.js?ver=v1/assets/frontend/fuse-search/dist/index.css?ver=v1

HTML / DOM Fingerprints

CSS Classes
fusecom-admin-settings-appfuse-search-wrapper
Data Attributes
data-fusecom-appdata-fusecom-search
JS Globals
FUSE_COM_ADMIN_SETTINGSFUSE_COM_APP_PUBLIC_URLFUSE_COM_APP_PATHfuse_com_frontend_settings
Shortcode Output
[ftl_product_search]
FAQ

Frequently Asked Questions about FtlCommerce – Instant Product Search