
jessyp AI Product Finder Security & Risk Analysis
wordpress.org/plugins/jessyp-ai-product-finderAI-powered semantic product search block that uses vector embeddings to find products based on natural language descriptions.
Is jessyp AI Product Finder Safe to Use in 2026?
Generally Safe
Score 100/100jessyp AI Product Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jessyp-ai-product-finder plugin v1.0.0 exhibits a generally good security posture with several strengths. The code shows a strong adherence to secure coding practices, evidenced by the complete absence of dangerous functions, raw SQL queries, and file operations. Furthermore, 100% of SQL queries utilize prepared statements, and a high percentage of outputs are properly escaped, mitigating common risks like SQL injection and cross-site scripting (XSS). The presence of nonces and capability checks on three entry points is also a positive indicator of security awareness.
However, the plugin is not without its concerns. The primary risk identified is a single REST API route that lacks permission callbacks. This means that this specific endpoint is accessible to any user, regardless of their WordPress role or capabilities, creating a potential pathway for unauthorized access or manipulation of data. While the taint analysis shows no immediate critical or high severity flows, this unprotected REST API route represents an unmitigated entry point that could be exploited if sensitive data is handled or if further vulnerabilities exist within that endpoint's logic.
Notably, the plugin has no recorded vulnerability history, which is a positive sign indicating a lack of past security flaws. This suggests the developers may have a good understanding of security principles. Despite this clean history, the single unprotected REST API route remains a critical weakness that needs immediate attention. The plugin's strengths in SQL handling and output escaping are commendable, but they do not negate the risk posed by an exposed API endpoint. A balanced conclusion is that the plugin has a strong foundation for security, but a significant flaw in its attack surface requires remediation.
Key Concerns
- REST API route without permission callback
- Unprotected entry point (REST API)
jessyp AI Product Finder Security Vulnerabilities
jessyp AI Product Finder Release Timeline
jessyp AI Product Finder Code Analysis
Output Escaping
jessyp AI Product Finder Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 5
Maintenance & Trust
jessyp AI Product Finder Maintenance & Trust
Maintenance Signals
Community Trust
jessyp AI Product Finder Alternatives
AI Search – Intelligent Search for WooCommerce and WordPress
ai-search
Replaces the default WordPress search with an AI-powered semantic search system. Perfect for WooCommerce stores and eCommerce sites. ---
AI Search for WooCommerce – Semantic Search
queryra-ai-search
Replaces WooCommerce search with AI semantic search. Understands customer intent — finds products even with natural language queries.
AI Vector Search (Semantic)
ai-vector-search-semantic
🚀 Transform your WooCommerce search with AI-powered semantic search. Get smarter product recommendations and blazing-fast search results.
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
Block Emails for WooCommerce Checkout
wc-block-emails
A WooCommerce plugin to block specific email addresses during checkout.
jessyp AI Product Finder Developer Profile
1 plugin · 0 total installs
How We Detect jessyp AI Product Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jessyp-ai-product-finder/build/index.js/wp-content/plugins/jessyp-ai-product-finder/build/style-index.css/wp-content/plugins/jessyp-ai-product-finder/build/index.jsjessyp-ai-product-finder/build/index.js?ver=jessyp-ai-product-finder/build/style-index.css?ver=HTML / DOM Fingerprints
wp-block-jessyp-ai-product-finder-searchai-product-finder-titleai-product-finder-searchsearch-input-containerai-search-inputsearch-buttonsearch-iconai-suggestion-chips+9 moredata-result-countdata-rest-url/wp-json/jessyp-ai-product-finder/v1/search