
RND Product Filters with ajax for WooCommerce Security & Risk Analysis
wordpress.org/plugins/rnd-wc-product-filters-with-ajaxWoocommerce Ajax Product Filter with that when you install this plugin that will auto change and load the product wihtout loading or refreshing the pa …
Is RND Product Filters with ajax for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100RND Product Filters with ajax for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'rnd-wc-product-filters-with-ajax' v1.3 exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries and appears to have no recorded vulnerabilities, the presence of two AJAX handlers lacking authentication checks is a significant weakness. This means that unauthenticated users could potentially interact with these AJAX endpoints, leading to unintended actions or information disclosure if malicious input is provided.
The static analysis shows a total of two AJAX entry points, both of which are unprotected. This is a direct and critical security concern. Although no dangerous functions, file operations, or external HTTP requests were detected, and SQL queries are properly prepared, the absence of capability checks and nonce checks on these critical AJAX handlers leaves a significant gap. The taint analysis also shows no critical or high-severity flows, which is positive, but it analyzed only one flow, suggesting the analysis might not be exhaustive.
Given the absence of any historical vulnerabilities and the good practices in SQL handling and output escaping (76% is decent, though could be improved), the plugin shows some promise. However, the two unprotected AJAX handlers are a serious oversight that significantly increases the risk profile. The current security posture is a mix of good practices and a critical oversight in access control for its entry points. A balanced conclusion is that while the plugin is not inherently malicious or poorly coded in many aspects, the unprotected AJAX endpoints represent a clear and present danger.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
- AJAX handlers without nonce checks
- Limited taint analysis coverage
- Output escaping not fully proper (76%)
RND Product Filters with ajax for WooCommerce Security Vulnerabilities
RND Product Filters with ajax for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
RND Product Filters with ajax for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
RND Product Filters with ajax for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
RND Product Filters with ajax for WooCommerce Alternatives
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
gs-logo-slider
Logo Slider: The best responsive plugin for Logo Showcase, Logo Carousel, and displaying clients' logos. Includes shortcode generator with preview!
Site Offline Or Coming Soon Or Maintenance Mode
site-offline
Site Offline plugin manage your WordPress website in under construction or maintenance mode or coming soon or landing page.
Quick Adsense
quick-adsense
Quick Adsense offers a quicker & flexible way to insert Google Adsense or any Ads code into a blog post.
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
RND Product Filters with ajax for WooCommerce Developer Profile
4 plugins · 180 total installs
How We Detect RND Product Filters with ajax for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/frontend.css/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/admin.css/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/frontend.css?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend.js?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/js/frontend-script.js?ver=/wp-content/plugins/rnd-wc-product-filters-with-ajax/assets/css/admin.css?ver=HTML / DOM Fingerprints
rndapf-widget-arearndapf-widgetrndapf-product-filter-widgetrndapf-taxonomy-filterrndapf-attribute-filterrndapf-price-filterrndapf-review-filterrndapf-chosendata-keydata-valuedata-multiple-filterrndapf_frontend_script_params