
WCAPF – Ajax Product Filter for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-ajax-product-filterFilter WooCommerce products by category, tag, attribute, price, rating, author, meta fields, and keyword using AJAX.
Is WCAPF – Ajax Product Filter for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100WCAPF – Ajax Product Filter for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wc-ajax-product-filter" plugin v4.3.0 presents a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and a substantial amount of output being properly escaped. The absence of known CVEs and a clean vulnerability history are also favorable indicators. However, a significant concern lies in its attack surface, with 17 AJAX handlers, 14 of which lack authentication checks. This creates a considerable entry point for potential abuse. While taint analysis shows no critical or high-severity issues, one flow with an unsanitized path warrants attention, as it could lead to unexpected behavior if exploited.
The plugin's reliance on raw PHP functions for file operations, though only one instance, could also be a minor concern if not handled with utmost care. The presence of bundled jQuery, while common, implies a potential dependency on an external library that might have its own vulnerabilities, though no specific issues are indicated in the provided data. Overall, the plugin has a solid foundation in data handling and output sanitization, but the lack of robust authentication on a majority of its AJAX endpoints is a notable weakness that attackers could target.
Key Concerns
- 14 unprotected AJAX handlers
- 1 unsanitized path in taint analysis
- 1 file operation instance
WCAPF – Ajax Product Filter for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WCAPF – WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection
WCAPF – Ajax Product Filter for WooCommerce Release Timeline
WCAPF – Ajax Product Filter for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WCAPF – Ajax Product Filter for WooCommerce Attack Surface
AJAX Handlers 17
Shortcodes 4
WordPress Hooks 50
Maintenance & Trust
WCAPF – Ajax Product Filter for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WCAPF – Ajax Product Filter for WooCommerce Alternatives
YITH WooCommerce Ajax Product Filter
yith-woocommerce-ajax-navigation
YITH WooCommerce Ajax Product Filter offers you the perfect way to filter all products of your WooCommerce shop.
Dynamic AJAX Product Filters for WooCommerce
dynamic-ajax-product-filters-for-woocommerce
Dynamic AJAX Product Filters allow shoppers to quickly filter WooCommerce products by categories, attributes, prices, and more.
Pofily – WooCommerce Product Filters
pofily-woo-product-filters
Easily add customizable filters to WooCommerce products with Pofily. Tailor filters to customer needs for seamless product searches.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Filter Everything — WordPress & WooCommerce Filters
filter-everything
The most flexible filters plugin for WordPress & WooCommerce – filter anything.
WCAPF – Ajax Product Filter for WooCommerce Developer Profile
3 plugins · 9K total installs
How We Detect WCAPF – Ajax Product Filter for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-ajax-product-filter/assets/css/frontend.css/wp-content/plugins/wc-ajax-product-filter/assets/js/frontend.js/wp-content/plugins/wc-ajax-product-filter/assets/js/frontend.jswc-ajax-product-filter/assets/css/frontend.css?ver=wc-ajax-product-filter/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wcapf-filter-wrapper<!-- WCAPF Filter Start --><!-- WCAPF Filter End -->data-wcapf-attributewcapf_frontend_params[wcapf_filter]