Tori Ajax Security & Risk Analysis

wordpress.org/plugins/tori-ajax

Adds Ajax in WordPress with a few lines of code. Adding Ajax is now simple as calling toria_add_ajax($action_name, $php_callback, $js_script_path) fun …

0 active installs v2.0.3 PHP 5.6.20+ WP 3.0.0+ Updated Mar 9, 2026
ajaxjavascripttoria_add_ajaxtori_ajax
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tori Ajax Safe to Use in 2026?

Generally Safe

Score 100/100

Tori Ajax has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "tori-ajax" plugin v2.0.3 demonstrates a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without proper authentication or permission checks. The code strictly adheres to secure coding practices, including 100% use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of file operations and external HTTP requests further reduces the potential attack surface. The plugin also incorporates nonce checks, which is a positive indicator of security awareness, though capability checks are absent.

Key Concerns

  • Missing capability checks
  • Bundled outdated Freemius v1.0 library
Vulnerabilities
None known

Tori Ajax Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tori Ajax Release Timeline

v2.0.3Current
v2.0.2
v2.0.1
v2.0.0
v1.2.0
v1.1.0
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Tori Ajax Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped12 total outputs
Attack Surface

Tori Ajax Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsincludes\ajax\class-toria-ajax.php:238
actionwp_enqueue_scriptsincludes\ajax\class-toria-ajax.php:248
actionplugins_loadedincludes\class-toria.php:203
actionadmin_enqueue_scriptsincludes\class-toria.php:295
actionadmin_enqueue_scriptsincludes\class-toria.php:296
actioninitincludes\class-toria.php:297
filterplugin_row_metaincludes\class-toria.php:298
actionafter_uninstalltoria.php:130
Maintenance & Trust

Tori Ajax Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 9, 2026
PHP min version5.6.20
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tori Ajax Developer Profile

alvinmuthui

3 plugins · 40 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tori Ajax

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tori-ajax/assets/js/toria-ajax.js/wp-content/plugins/tori-ajax/assets/css/toria-ajax.css
Script Paths
/wp-content/plugins/tori-ajax/assets/js/toria-ajax.js
Version Parameters
tori-ajax/assets/js/toria-ajax.js?ver=tori-ajax/assets/css/toria-ajax.css?ver=

HTML / DOM Fingerprints

JS Globals
toria_ajax_obj
FAQ

Frequently Asked Questions about Tori Ajax