YMM Product Filter for Woo – Year Make Model search Security & Risk Analysis

wordpress.org/plugins/tyresaddict-ymm-product-filter

Filter and search products using Year Make Model. Finder widgets for pages with Elementor support, import/export YMM data.

10 active installs v1.5.2 PHP 7.4+ WP 6.2+ Updated Mar 4, 2026
auto-partsautomotiveecommerceproduct-filterymm-filter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YMM Product Filter for Woo – Year Make Model search Safe to Use in 2026?

Generally Safe

Score 100/100

YMM Product Filter for Woo – Year Make Model search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "tyresaddict-ymm-product-filter" v1.5.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping a high percentage of its output. The absence of known CVEs and a clean vulnerability history suggest a relatively secure development track record. However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This exposes a direct attack surface without proper authorization, potentially allowing unauthorized users to trigger plugin functionalities.

The static analysis revealed no critical or high-severity taint flows, which is a strong indicator of secure handling of user-supplied data for these analyzed paths. The plugin also has a limited number of file operations and makes no external HTTP requests, further reducing potential attack vectors. Despite the strong data sanitization and escaping practices, the unprotected AJAX endpoints are a notable weakness that could be exploited if those handlers perform sensitive actions. The plugin's vulnerability history is empty, which is a positive sign, but it does not negate the risks identified in the current code analysis. Overall, while the plugin has several security strengths, the unprotected AJAX endpoints represent a clear and present risk that should be addressed.

Key Concerns

  • Unprotected AJAX handlers found
Vulnerabilities
None known

YMM Product Filter for Woo – Year Make Model search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YMM Product Filter for Woo – Year Make Model search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
39 prepared
Unescaped Output
37
501 escaped
Nonce Checks
1
Capability Checks
6
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared39 total queries

Output Escaping

93% escaped538 total outputs
Attack Surface
2 unprotected

YMM Product Filter for Woo – Year Make Model search Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_tyresaddict_ymmincludes\PluginPublic.php:33
noprivwp_ajax_tyresaddict_ymmincludes\PluginPublic.php:34
WordPress Hooks 27
actionadmin_bar_menuincludes\FeatureFilterDebug.php:19
actionadmin_action_ymmfp_exportincludes\FeatureImEx.php:21
actionadmin_action_ymmfp_truncateincludes\FeatureImEx.php:22
filterwoocommerce_product_data_tabsincludes\FeatureProductData.php:22
actionwoocommerce_product_data_panelsincludes\FeatureProductData.php:23
actionwoocommerce_process_product_metaincludes\FeatureProductData.php:27
filterwoocommerce_product_tabsincludes\FeatureProductTab.php:20
actionadmin_menuincludes\FeatureProMenu.php:21
actionadmin_menuincludes\FeatureProMenu.php:38
actionelementor/widgets/registerincludes\FeatureWidgets.php:27
actionelementor/elements/categories_registeredincludes\FeatureWidgets.php:33
actioncustomize_registerincludes\FilterWidget.php:39
actionwidgets_initincludes\FinderWidget.php:55
actionadmin_menuincludes\PageOptions.php:31
actionadmin_initincludes\PageOptions.php:32
actionadmin_enqueue_scriptsincludes\Plugin.php:117
actionadmin_enqueue_scriptsincludes\Plugin.php:118
actionwp_enqueue_scriptsincludes\Plugin.php:144
actionwp_enqueue_scriptsincludes\Plugin.php:145
actionwoocommerce_product_queryincludes\PluginPublic.php:31
filtertyresaddict/ymm-filter/debug/stateincludes\PluginPublic.php:40
filtertyresaddict/ymm-filter/debug/stateincludes\PluginPublic.php:45
filtertyresaddict/ymm-filter/debug/modeincludes\PluginPublic.php:46
filtertyresaddict/ymm-filter/debug/filtersincludes\PluginPublic.php:53
actionadmin_noticesincludes\Woo.php:352
actionplugins_loadedtyresaddict-ymm-product-filter.php:78
actionwidgets_inittyresaddict-ymm-product-filter.php:91
Maintenance & Trust

YMM Product Filter for Woo – Year Make Model search Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads403

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YMM Product Filter for Woo – Year Make Model search Developer Profile

TyresAddict

5 plugins · 370 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YMM Product Filter for Woo – Year Make Model search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tyresaddict-ymm-product-filter/css/tyresaddict-ymm-product-filter.css/wp-content/plugins/tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.js
Script Paths
/wp-content/plugins/tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.js
Version Parameters
tyresaddict-ymm-product-filter/css/tyresaddict-ymm-product-filter.css?ver=tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.js?ver=

HTML / DOM Fingerprints

CSS Classes
tyresaddict-ymm-filter-widget-pro
Data Attributes
data-iddata-element_typedata-settings
JS Globals
tyresaddict_ymm
Shortcode Output
[tyresaddict-ymm-filter]
FAQ

Frequently Asked Questions about YMM Product Filter for Woo – Year Make Model search