
Year Make Model Search for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ymm-searchIt will find products for selected make and model.
Is Year Make Model Search for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Year Make Model Search for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'ymm-search' plugin v1.0.12 exhibits a mixed security posture. While it has no known unpatched vulnerabilities, the static analysis reveals several significant concerns. A large portion of its attack surface, specifically 5 out of 6 entry points, lacks proper authentication checks. This is further exacerbated by taint analysis indicating 4 high-severity flows with unsanitized paths, suggesting potential for data manipulation or injection if these paths are reached.
The plugin's vulnerability history shows a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which, while now patched, indicates a potential for such issues. The static analysis also highlights poor output escaping practices, with only 8% of outputs properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of raw SQL queries without prepared statements in 26% of cases (7 out of 19) is also a concern for SQL injection.
Overall, the plugin has strengths in its lack of external HTTP requests and a decent percentage of SQL queries using prepared statements. However, the high number of unprotected entry points, critical taint flows, and insufficient output escaping significantly outweigh these strengths, presenting a notable risk to WordPress installations.
Key Concerns
- High number of unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- SQL queries not using prepared statements
- Past medium severity vulnerability (CSRF)
Year Make Model Search for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Year Make Model Search for WooCommerce <= 1.0.11 - Cross-Site Request Forgery
Year Make Model Search for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Year Make Model Search for WooCommerce Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Year Make Model Search for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Year Make Model Search for WooCommerce Alternatives
SEMA API
sema-api
The plugin is built to automatically transfer auto parts data from SEMA Data Coop to Wordpress/wooCommerce. A comprehensive frontend catalog search p …
YMM Product Filter for Woo – Year Make Model search
tyresaddict-ymm-product-filter
Filter and search products using Year Make Model. Finder widgets for pages with Elementor support, import/export YMM data.
Year Make Model Search for WooCommerce Developer Profile
14 plugins · 6K total installs
How We Detect Year Make Model Search for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ymm-search/view/adminhtml/web/ymm/main.css/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.js/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.css/wp-content/plugins/ymm-search/view/frontend/web/main.js/wp-content/plugins/ymm-search/view/frontend/web/main.css/wp-content/plugins/ymm-search/view/frontend/web/product/restriction.css/wp-content/plugins/ymm-search/view/adminhtml/web/ymm/main.css/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.js/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.css/wp-content/plugins/ymm-search/view/frontend/web/main.js/wp-content/plugins/ymm-search/view/frontend/web/main.css/wp-content/plugins/ymm-search/view/frontend/web/product/restriction.cssymm-search/view/adminhtml/web/ymm/main.css?ver=ymm-search/view/adminhtml/web/product/edit/main.js?ver=ymm-search/view/adminhtml/web/product/edit/main.css?ver=ymm-search/view/frontend/web/main.js?ver=ymm-search/view/frontend/web/main.css?ver=ymm-search/view/frontend/web/product/restriction.css?ver=HTML / DOM Fingerprints
ymm-selector-widgetymm-horizontal-selector-widgetymm-product-restriction-tabymm-admin-manage-selector<!-- YMM SEARCH START --><!-- YMM SEARCH END --><!-- YMM SEARCH FOR GARAGE START --><!-- YMM SEARCH FOR GARAGE END -->data-ymm-selector-widget-iddata-ymm-garage-enableddata-ymm-remove-from-garage-enableddata-ymm-filter-category-pagedata-ymm-templateymm_selector_paramsYmmSelector/wp-json/ymm/v1/selector/fetch/wp-json/ymm/v1/selector/categories/wp-json/ymm/v1/restriction/search<div class="ymm-selector-widget"<div class="ymm-horizontal-selector-widget"