RND Product Filters with ajax for WooCommerce Security & Risk Analysis

wordpress.org/plugins/rnd-wc-product-filters-with-ajax

Woocommerce Ajax Product Filter with that when you install this plugin that will auto change and load the product wihtout loading or refreshing the pa …

0 active installs v1.3 PHP 5.5.0+ WP 4.0+ Updated Jan 20, 2025
woocommerce-ajax-product-filterwoocommerce-ajax-product-reviewswoocommerce-ajax-product-searchwordpress-plugin
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RND Product Filters with ajax for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

RND Product Filters with ajax for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'rnd-wc-product-filters-with-ajax' v1.3 exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries and appears to have no recorded vulnerabilities, the presence of two AJAX handlers lacking authentication checks is a significant weakness. This means that unauthenticated users could potentially interact with these AJAX endpoints, leading to unintended actions or information disclosure if malicious input is provided.

The static analysis shows a total of two AJAX entry points, both of which are unprotected. This is a direct and critical security concern. Although no dangerous functions, file operations, or external HTTP requests were detected, and SQL queries are properly prepared, the absence of capability checks and nonce checks on these critical AJAX handlers leaves a significant gap. The taint analysis also shows no critical or high-severity flows, which is positive, but it analyzed only one flow, suggesting the analysis might not be exhaustive.

Given the absence of any historical vulnerabilities and the good practices in SQL handling and output escaping (76% is decent, though could be improved), the plugin shows some promise. However, the two unprotected AJAX handlers are a serious oversight that significantly increases the risk profile. The current security posture is a mix of good practices and a critical oversight in access control for its entry points. A balanced conclusion is that while the plugin is not inherently malicious or poorly coded in many aspects, the unprotected AJAX endpoints represent a clear and present danger.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without capability checks
  • AJAX handlers without nonce checks
  • Limited taint analysis coverage
  • Output escaping not fully proper (76%)
Vulnerabilities
None known

RND Product Filters with ajax for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

RND Product Filters with ajax for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
28
87 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared1 total queries

Output Escaping

76% escaped115 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<active-filter> (ajax\templates\active-filter.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

RND Product Filters with ajax for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_filter_productsajax\includes\hooks.php:17
noprivwp_ajax_filter_productsajax\includes\hooks.php:18
WordPress Hooks 19
filterrndapf_settingsajax\filters.php:15
actionwoocommerce_before_shop_loopajax\includes\hooks.php:13
actionwoocommerce_after_shop_loopajax\includes\hooks.php:14
actionwoocommerce_after_shop_loopajax\includes\hooks.php:16
actionpaginate_linksajax\includes\hooks.php:20
actionwp_enqueue_scriptsajax\includes\hooks.php:23
actioncreate_termajax\includes\hooks.php:29
actionedit_termajax\includes\hooks.php:30
actiondelete_termajax\includes\hooks.php:31
actionsave_postajax\includes\hooks.php:33
actiondelete_postajax\includes\hooks.php:34
actionplugins_loadedajax\rndapf.php:41
actioninitajax\rndapf.php:67
actionadmin_noticesajax\rndapf.php:84
actionadmin_noticesajax\rndapf.php:88
actionadmin_menuajax\rndapf.php:160
actionadmin_initajax\rndapf.php:161
actionadmin_initajax\rndapf.php:162
actionwidgets_initajax\widgets\widget-category-filter.php:252
Maintenance & Trust

RND Product Filters with ajax for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 20, 2025
PHP min version5.5.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

RND Product Filters with ajax for WooCommerce Developer Profile

webrndexperts

4 plugins · 180 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RND Product Filters with ajax for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/frontend.css/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/admin.css
Script Paths
/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js
Version Parameters
/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/frontend.css?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
rndapf-widget-arearndapf-widgetrndapf-product-filter-widgetrndapf-taxonomy-filterrndapf-attribute-filterrndapf-price-filterrndapf-review-filterrndapf-chosen
Data Attributes
data-keydata-valuedata-multiple-filter
JS Globals
rndapf_frontend_script_params
FAQ

Frequently Asked Questions about RND Product Filters with ajax for WooCommerce