NivoSearch – Ajax Product Search for WooCommerce Security & Risk Analysis

wordpress.org/plugins/nivo-ajax-search-for-woocommerce

Ajax Product Search for WooCommerce with instant live results, smart relevance, SKU search, and fuzzy matching to boost conversions.

0 active installs v1.1.1 PHP 7.4+ WP 5.0+ Updated Jan 23, 2026
ajax-product-search-for-woocommerceajax-search-woocommercelive-product-searchsku-search-woocommercewoocommerce-product-search
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NivoSearch – Ajax Product Search for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

NivoSearch – Ajax Product Search for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of 'nivo-ajax-search-for-woocommerce' v1.1.1 reveals a generally strong security posture, with several good practices in place. The code utilizes prepared statements for all SQL queries and exhibits high output escaping percentages, significantly mitigating common injection vulnerabilities. The presence of nonce and capability checks on entry points is also a positive indicator. Furthermore, the complete absence of known CVEs and a clean vulnerability history suggest a commitment to security or a lack of past exploitable issues.

However, the presence of two AJAX handlers without explicit authentication checks presents a potential concern. While the total entry points are low, these unprotected handlers could become a target for unauthorized access or denial-of-service attacks if not properly secured within the application logic. The lack of taint analysis data makes it difficult to fully assess the risk associated with data flowing through these handlers, but the absence of explicit checks is a point of caution. Despite this, the overall picture is one of a relatively secure plugin, with the primary area for improvement being the authentication of AJAX endpoints.

Key Concerns

  • AJAX handlers without auth checks
Vulnerabilities
None known

NivoSearch – Ajax Product Search for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NivoSearch – Ajax Product Search for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
82 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

96% escaped85 total outputs
Attack Surface

NivoSearch – Ajax Product Search for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_nivo_searchincludes\classes\Nivo_Ajax_Search.php:117
noprivwp_ajax_nivo_searchincludes\classes\Nivo_Ajax_Search.php:118

Shortcodes 1

[nivo_search] includes\classes\Shortcode.php:44
WordPress Hooks 21
actionadmin_menuincludes\admin\Admin_Settings.php:31
actionadmin_headincludes\admin\Admin_Settings.php:32
actionadmin_headincludes\admin\Admin_Settings.php:33
actionwp_enqueue_scriptsincludes\classes\Enqueue.php:62
actionadmin_enqueue_scriptsincludes\classes\Enqueue.php:63
actioninitincludes\classes\Gutenberg_Block.php:28
actionenqueue_block_editor_assetsincludes\classes\Gutenberg_Block.php:29
actionwc_ajax_nivo_searchincludes\classes\Nivo_Ajax_Search.php:119
filterposts_searchincludes\classes\Search_Algorithm.php:68
filterposts_joinincludes\classes\Search_Algorithm.php:69
filterposts_distinctincludes\classes\Search_Algorithm.php:70
actioninitincludes\classes\Search_Preset_CPT.php:24
actionadd_meta_boxesincludes\classes\Search_Preset_CPT.php:25
actionsave_post_nivo_search_presetincludes\classes\Search_Preset_CPT.php:26
filtermanage_nivo_search_preset_posts_columnsincludes\classes\Search_Preset_CPT.php:27
actionmanage_nivo_search_preset_posts_custom_columnincludes\classes\Search_Preset_CPT.php:28
actionwp_footerincludes\classes\Shortcode.php:45
actionbefore_delete_postincludes\classes\Shortcode.php:46
filterbefore_woocommerce_initnivo-ajax-search-for-woocommerce.php:47
actionplugins_loadednivo-ajax-search-for-woocommerce.php:67
filterplugin_row_metanivo-ajax-search-for-woocommerce.php:184
Maintenance & Trust

NivoSearch – Ajax Product Search for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 23, 2026
PHP min version7.4
Downloads394

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

NivoSearch – Ajax Product Search for WooCommerce Developer Profile

Nazmun Sakib

5 plugins · 10 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NivoSearch – Ajax Product Search for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nivo-ajax-search-for-woocommerce/assets/css/admin.css/wp-content/plugins/nivo-ajax-search-for-woocommerce/assets/js/admin.js/wp-content/plugins/nivo-ajax-search-for-woocommerce/assets/js/nivo-search.js
Script Paths
assets/js/nivo-search.jsassets/js/admin.js
Version Parameters
nivo-ajax-search-for-woocommerce/assets/css/admin.css?ver=nivo-ajax-search-for-woocommerce/assets/js/admin.js?ver=nivo-ajax-search-for-woocommerce/assets/js/nivo-search.js?ver=

HTML / DOM Fingerprints

CSS Classes
nivo-search-wrap
Data Attributes
data-nivo-search
JS Globals
nivo_search_params
FAQ

Frequently Asked Questions about NivoSearch – Ajax Product Search for WooCommerce