
YMM Product Filter for Woo – Year Make Model search Security & Risk Analysis
wordpress.org/plugins/tyresaddict-ymm-product-filterFilter and search products using Year Make Model. Finder widgets for pages with Elementor support, import/export YMM data.
Is YMM Product Filter for Woo – Year Make Model search Safe to Use in 2026?
Generally Safe
Score 100/100YMM Product Filter for Woo – Year Make Model search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tyresaddict-ymm-product-filter" v1.5.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping a high percentage of its output. The absence of known CVEs and a clean vulnerability history suggest a relatively secure development track record. However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This exposes a direct attack surface without proper authorization, potentially allowing unauthorized users to trigger plugin functionalities.
The static analysis revealed no critical or high-severity taint flows, which is a strong indicator of secure handling of user-supplied data for these analyzed paths. The plugin also has a limited number of file operations and makes no external HTTP requests, further reducing potential attack vectors. Despite the strong data sanitization and escaping practices, the unprotected AJAX endpoints are a notable weakness that could be exploited if those handlers perform sensitive actions. The plugin's vulnerability history is empty, which is a positive sign, but it does not negate the risks identified in the current code analysis. Overall, while the plugin has several security strengths, the unprotected AJAX endpoints represent a clear and present risk that should be addressed.
Key Concerns
- Unprotected AJAX handlers found
YMM Product Filter for Woo – Year Make Model search Security Vulnerabilities
YMM Product Filter for Woo – Year Make Model search Code Analysis
SQL Query Safety
Output Escaping
YMM Product Filter for Woo – Year Make Model search Attack Surface
AJAX Handlers 2
WordPress Hooks 27
Maintenance & Trust
YMM Product Filter for Woo – Year Make Model search Maintenance & Trust
Maintenance Signals
Community Trust
YMM Product Filter for Woo – Year Make Model search Alternatives
TyresAddict – Tyre Product Filter for WooCommerce
tyresaddict-woo-tyre-product-filter
Tyre Product Filter help shoppers find tyres on WooCommerce shop. Filter tyres by size, season, car type and tyre brand.
TyresAddict – Tyre Custom Metadata for WooCommerce
tyresaddict-woo-tyre-custom-metadata
Create custom tyre (size specification, season, vehicle, etc) and wheel metadata via MetaBox for WooCommerce Products. Show on product pages, edit.
TyresAddict – Wheel Product Filter
tyresaddict-wheel-product-filter
Wheel Product Filter help shoppers find wheels on WooCommerce shop. Filter wheels by size, type and wheel brand.
SiteEase Smart AJAX Product Filter
siteease-smart-product-filtering-engine
SiteEase Smart AJAX Product Filter plugin allows customers to filter WooCommerce products instantly using AJAX, without page reloads.
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
YMM Product Filter for Woo – Year Make Model search Developer Profile
5 plugins · 370 total installs
How We Detect YMM Product Filter for Woo – Year Make Model search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tyresaddict-ymm-product-filter/css/tyresaddict-ymm-product-filter.css/wp-content/plugins/tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.js/wp-content/plugins/tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.jstyresaddict-ymm-product-filter/css/tyresaddict-ymm-product-filter.css?ver=tyresaddict-ymm-product-filter/js/tyresaddict-ymm-product-filter.js?ver=HTML / DOM Fingerprints
tyresaddict-ymm-filter-widget-prodata-iddata-element_typedata-settingstyresaddict_ymm[tyresaddict-ymm-filter]