
Year Make Model Search for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ymm-searchIt will find products for selected make and model.
Is Year Make Model Search for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Year Make Model Search for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'ymm-search' plugin v1.0.12 exhibits a mixed security posture. While it has no known unpatched vulnerabilities, the static analysis reveals several significant concerns. A large portion of its attack surface, specifically 5 out of 6 entry points, lacks proper authentication checks. This is further exacerbated by taint analysis indicating 4 high-severity flows with unsanitized paths, suggesting potential for data manipulation or injection if these paths are reached.
The plugin's vulnerability history shows a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which, while now patched, indicates a potential for such issues. The static analysis also highlights poor output escaping practices, with only 8% of outputs properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of raw SQL queries without prepared statements in 26% of cases (7 out of 19) is also a concern for SQL injection.
Overall, the plugin has strengths in its lack of external HTTP requests and a decent percentage of SQL queries using prepared statements. However, the high number of unprotected entry points, critical taint flows, and insufficient output escaping significantly outweigh these strengths, presenting a notable risk to WordPress installations.
Key Concerns
- High number of unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- SQL queries not using prepared statements
- Past medium severity vulnerability (CSRF)
Year Make Model Search for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Year Make Model Search for WooCommerce <= 1.0.11 - Cross-Site Request Forgery
Year Make Model Search for WooCommerce Release Timeline
Year Make Model Search for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Year Make Model Search for WooCommerce Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Year Make Model Search for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Year Make Model Search for WooCommerce Alternatives
SEMA API
sema-api
The plugin is built to automatically transfer auto parts data from SEMA Data Coop to Wordpress/wooCommerce. A comprehensive frontend catalog search p …
YMM Product Filter for Woo – Year Make Model search
tyresaddict-ymm-product-filter
Filter and search products using Year Make Model. Finder widgets for pages with Elementor support, import/export YMM data.
Year Make Model Search for WooCommerce Developer Profile
15 plugins · 6K total installs
How We Detect Year Make Model Search for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ymm-search/view/adminhtml/web/ymm/main.css/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.js/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.css/wp-content/plugins/ymm-search/view/frontend/web/main.js/wp-content/plugins/ymm-search/view/frontend/web/main.css/wp-content/plugins/ymm-search/view/frontend/web/product/restriction.css/wp-content/plugins/ymm-search/view/adminhtml/web/ymm/main.css/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.js/wp-content/plugins/ymm-search/view/adminhtml/web/product/edit/main.css/wp-content/plugins/ymm-search/view/frontend/web/main.js/wp-content/plugins/ymm-search/view/frontend/web/main.css/wp-content/plugins/ymm-search/view/frontend/web/product/restriction.cssymm-search/view/adminhtml/web/ymm/main.css?ver=ymm-search/view/adminhtml/web/product/edit/main.js?ver=ymm-search/view/adminhtml/web/product/edit/main.css?ver=ymm-search/view/frontend/web/main.js?ver=ymm-search/view/frontend/web/main.css?ver=ymm-search/view/frontend/web/product/restriction.css?ver=HTML / DOM Fingerprints
ymm-selector-widgetymm-horizontal-selector-widgetymm-product-restriction-tabymm-admin-manage-selector<!-- YMM SEARCH START --><!-- YMM SEARCH END --><!-- YMM SEARCH FOR GARAGE START --><!-- YMM SEARCH FOR GARAGE END -->data-ymm-selector-widget-iddata-ymm-garage-enableddata-ymm-remove-from-garage-enableddata-ymm-filter-category-pagedata-ymm-templateymm_selector_paramsYmmSelector/wp-json/ymm/v1/selector/fetch/wp-json/ymm/v1/selector/categories/wp-json/ymm/v1/restriction/search<div class="ymm-selector-widget"<div class="ymm-horizontal-selector-widget"