
WC Filter By Multiple Tax Security & Risk Analysis
wordpress.org/plugins/wc-filter-by-multiple-taxWC Filter By Multiple Tax is an e-commerce toolkit that helps you filter products by multiple taxonomy (Product category, Product Feature, Product Bra …
Is WC Filter By Multiple Tax Safe to Use in 2026?
Generally Safe
Score 85/100WC Filter By Multiple Tax has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-filter-by-multiple-tax" v1.1.0 plugin exhibits a concerning security posture primarily due to its unprotected AJAX endpoints. While the plugin shows strengths in its handling of SQL queries, utilizing prepared statements exclusively, and avoiding dangerous functions, file operations, or external HTTP requests, the presence of two AJAX handlers without authentication checks creates a significant attack surface. This lack of authorization means any unauthenticated user could potentially interact with these endpoints, leading to unintended consequences or exploitation of underlying logic within the plugin.
The static analysis reveals that a substantial portion of output (41%) is not properly escaped. While taint analysis shows no detected vulnerabilities in this version, the combination of unescaped output and unprotected AJAX handlers presents a plausible pathway for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within these AJAX operations. The absence of any recorded vulnerabilities in its history might indicate a lack of historical targeting or that previous versions were more secure. However, this should not be relied upon as a sole indicator of current security.
In conclusion, the plugin's use of prepared statements and lack of other common risky code patterns are positive signs. Nevertheless, the two unprotected AJAX endpoints are a critical weakness that requires immediate attention. Coupled with the significant percentage of unescaped output, the plugin's current security is compromised. Addressing the unprotected AJAX handlers and improving output escaping are essential steps to mitigate the identified risks.
Key Concerns
- 2 AJAX handlers without auth checks
- 59% properly escaped output (41% unescaped)
- 0 Nonce checks
- 0 Capability checks
WC Filter By Multiple Tax Security Vulnerabilities
WC Filter By Multiple Tax Code Analysis
SQL Query Safety
Output Escaping
WC Filter By Multiple Tax Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
WC Filter By Multiple Tax Maintenance & Trust
Maintenance Signals
Community Trust
WC Filter By Multiple Tax Alternatives
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
Shopify Importer
shopify
Import products from a Shopify.com online store into your blog.
Shift4Shop Online Store
3dcart-wp-online-store
Shift4Shop Online Store provides a streamlined way to sell any number of products from your Shift4Shop store directly on your WordPress blog.
CommerceBird
commercebird
Elevate WooCommerce to the next level by turning it into a complete ERP system.
WC Filter By Multiple Tax Developer Profile
1 plugin · 10 total installs
How We Detect WC Filter By Multiple Tax
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-filter-by-multiple-tax/assets/css/frontend.css/wp-content/plugins/wc-filter-by-multiple-tax/assets/js/frontend.js/wp-content/plugins/wc-filter-by-multiple-tax/assets/js/frontend.min.js/wp-content/plugins/wc-filter-by-multiple-tax/assets/css/frontend.min.css/wp-content/plugins/wc-filter-by-multiple-tax/assets/js/frontend.js/wp-content/plugins/wc-filter-by-multiple-tax/assets/js/frontend.min.jswc-filter-by-multiple-tax/assets/css/frontend.css?ver=wc-filter-by-multiple-tax/assets/js/frontend.js?ver=wc-filter-by-multiple-tax/assets/js/frontend.min.js?ver=wc-filter-by-multiple-tax/assets/css/frontend.min.css?ver=HTML / DOM Fingerprints
widget-taxonomy-menudata-tax-iddata-tax-namedata-valuedata-parentwc_filter_params