
Query Filter Security & Risk Analysis
wordpress.org/plugins/query-filterAdvanced taxonomy and Custom Fields CPT filtering plugin.
Is Query Filter Safe to Use in 2026?
Generally Safe
Score 85/100Query Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'query-filter' plugin, version 0.0.2, presents a significant security risk due to its unprotected AJAX handlers. The static analysis reveals four AJAX entry points, all of which lack any authentication or authorization checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure. Furthermore, the plugin exhibits a complete lack of output escaping for all 12 identified outputs, making it highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. While the plugin doesn't use dangerous functions or perform raw SQL queries, and has no recorded vulnerability history, these strengths are overshadowed by the critical flaws in its input handling and output sanitization. The absence of nonce and capability checks on AJAX actions, combined with the lack of output escaping, creates a dangerous attack surface.
Key Concerns
- AJAX handlers without authentication checks
- No output escaping for any output
- No nonce checks on AJAX actions
- No capability checks on AJAX actions
Query Filter Security Vulnerabilities
Query Filter Code Analysis
Output Escaping
Query Filter Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
Query Filter Maintenance & Trust
Maintenance Signals
Community Trust
Query Filter Alternatives
powerSearch for bbPress
gd-power-search-for-bbpress
Enhanced and powerful search for bbPress powered forums, with options to filter results by various criteria.
ACF Advanced Search
acf-advanced-search
Advanced search for the Advanced Custom Fields plugin (Free & Pro).
Frontier Query
frontier-query
Display list and grouping of posts in widgets, posts and pages. Breakdown posts by categories, taxonomies, date, post type etc.
Filter Search Page
filter-search-page
This plugin will help you to filter the search page results by category and post type.
VISeek – Easy Custom Search
viseek-easy-custom-search
Easy custom WP search with AJAX, smart filters, and stopword support. Lets you add multiple customizable forms and reports user searches for insights.
Query Filter Developer Profile
1 plugin · 100 total installs
How We Detect Query Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/query-filter/js/jquery.deserialize.js/wp-content/plugins/query-filter/js/purl.js/wp-content/plugins/query-filter/js/j-query-filter.js/wp-content/plugins/query-filter/js/j-query-filter.jsquery-filter/js/j-query-filter.js?ver=query-filter/css/HTML / DOM Fingerprints
eotnoResultsdata-lpJ_QUERY_FILTER_V<div hidden data-lp=<div hidden class="eot"></div><div class="noResults">