
TTT Loadmore Security & Risk Analysis
wordpress.org/plugins/ttt-loadmoreWordPress plugin to load more event with your own template.
Is TTT Loadmore Safe to Use in 2026?
Generally Safe
Score 85/100TTT Loadmore has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ttt-loadmore" plugin v1.1.1 exhibits a mixed security posture. On the positive side, the code analysis reveals good development practices such as the complete absence of dangerous functions, a 100% usage of prepared statements for SQL queries, and 100% properly escaped output. There are no file operations, external HTTP requests, or bundled libraries, which reduces the potential attack surface from these vectors. The vulnerability history is also clear, with no recorded CVEs, indicating a potentially stable and well-maintained codebase regarding past exploits.
However, a significant concern arises from the static analysis of the attack surface. The plugin exposes two AJAX handlers, both of which lack any authentication or capability checks. This means any unauthenticated user can trigger these AJAX actions, opening a direct pathway for potential abuse. The absence of nonces further exacerbates this issue, as it allows for Cross-Site Request Forgery (CSRF) attacks against these unprotected AJAX endpoints. While taint analysis shows no critical or high severity unsanitized flows, the lack of authentication on such prominent entry points is a critical oversight.
In conclusion, while the plugin demonstrates strong internal coding hygiene for SQL and output handling, the severe lack of security checks on its AJAX endpoints represents a substantial risk. The absence of nonces and capability checks on these two entry points makes them prime targets for unauthorized actions. This weakness outweighs the otherwise positive aspects of the code's internal security, making it a significant concern.
Key Concerns
- 2 AJAX handlers without auth checks
- 0 Nonce checks on AJAX handlers
TTT Loadmore Security Vulnerabilities
TTT Loadmore Code Analysis
TTT Loadmore Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
TTT Loadmore Maintenance & Trust
Maintenance Signals
Community Trust
TTT Loadmore Alternatives
Alphabetic Pagination
alphabetic-pagination
Alphabetic Pagination allows you to enable pagination on pages, posts, categories and WooCommerce shop page.
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
Load More Products for WooCommerce
load-more-products-for-woocommerce
Load products from next page via AJAX with infinite scrolling or load more products button
WP-Paginate
wp-paginate
WP-Paginate is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site.
YITH Infinite Scrolling
yith-infinite-scrolling
Add infinite scrolling to archive post or shop page.
TTT Loadmore Developer Profile
1 plugin · 10 total installs
How We Detect TTT Loadmore
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ttt-loadmore/template/front/js/loadmore.jswp-content/plugins/ttt-loadmore/template/front/js/loadmore.jsttt-loadmore/template/front/js/loadmore.js?ver=HTML / DOM Fingerprints
data-tttloadmoretttloadmoreConf