jessyp AI Product Finder Security & Risk Analysis

wordpress.org/plugins/jessyp-ai-product-finder

AI-powered semantic product search block that uses vector embeddings to find products based on natural language descriptions.

0 active installs v1.0.0 PHP 7.4+ WP 6.7+ Updated Mar 7, 2026
aiblocksearchsemanticwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is jessyp AI Product Finder Safe to Use in 2026?

Generally Safe

Score 100/100

jessyp AI Product Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The jessyp-ai-product-finder plugin v1.0.0 exhibits a generally good security posture with several strengths. The code shows a strong adherence to secure coding practices, evidenced by the complete absence of dangerous functions, raw SQL queries, and file operations. Furthermore, 100% of SQL queries utilize prepared statements, and a high percentage of outputs are properly escaped, mitigating common risks like SQL injection and cross-site scripting (XSS). The presence of nonces and capability checks on three entry points is also a positive indicator of security awareness.

However, the plugin is not without its concerns. The primary risk identified is a single REST API route that lacks permission callbacks. This means that this specific endpoint is accessible to any user, regardless of their WordPress role or capabilities, creating a potential pathway for unauthorized access or manipulation of data. While the taint analysis shows no immediate critical or high severity flows, this unprotected REST API route represents an unmitigated entry point that could be exploited if sensitive data is handled or if further vulnerabilities exist within that endpoint's logic.

Notably, the plugin has no recorded vulnerability history, which is a positive sign indicating a lack of past security flaws. This suggests the developers may have a good understanding of security principles. Despite this clean history, the single unprotected REST API route remains a critical weakness that needs immediate attention. The plugin's strengths in SQL handling and output escaping are commendable, but they do not negate the risk posed by an exposed API endpoint. A balanced conclusion is that the plugin has a strong foundation for security, but a significant flaw in its attack surface requires remediation.

Key Concerns

  • REST API route without permission callback
  • Unprotected entry point (REST API)
Vulnerabilities
None known

jessyp AI Product Finder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

jessyp AI Product Finder Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

jessyp AI Product Finder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
35 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

88% escaped40 total outputs
Attack Surface
1 unprotected

jessyp AI Product Finder Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 3

authwp_ajax_jessaipf_create_indexjessyp-ai-product-finder.php:98
authwp_ajax_jessaipf_update_indexjessyp-ai-product-finder.php:99
authwp_ajax_jessaipf_get_index_infojessyp-ai-product-finder.php:100

REST API Routes 1

POST/wp-json/jessyp-ai-product-finder/v1/searchjessyp-ai-product-finder.php:70
WordPress Hooks 5
actionadmin_menuincludes\class-jessaipf-admin-settings.php:28
actionadmin_initincludes\class-jessaipf-admin-settings.php:29
actionadmin_enqueue_scriptsincludes\class-jessaipf-admin-settings.php:30
actioninitjessyp-ai-product-finder.php:64
actionrest_api_initjessyp-ai-product-finder.php:93
Maintenance & Trust

jessyp AI Product Finder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 7, 2026
PHP min version7.4
Downloads208

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

jessyp AI Product Finder Developer Profile

jessyp

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect jessyp AI Product Finder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jessyp-ai-product-finder/build/index.js/wp-content/plugins/jessyp-ai-product-finder/build/style-index.css
Script Paths
/wp-content/plugins/jessyp-ai-product-finder/build/index.js
Version Parameters
jessyp-ai-product-finder/build/index.js?ver=jessyp-ai-product-finder/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-jessyp-ai-product-finder-searchai-product-finder-titleai-product-finder-searchsearch-input-containerai-search-inputsearch-buttonsearch-iconai-suggestion-chips+9 more
Data Attributes
data-result-countdata-rest-url
REST Endpoints
/wp-json/jessyp-ai-product-finder/v1/search
FAQ

Frequently Asked Questions about jessyp AI Product Finder