ACME Amazing Search Security & Risk Analysis

wordpress.org/plugins/acme-amazing-search

Acme Amazing Search is a simple google style ultra fast search engine that allows you to search anything inside WordPress.

10 active installs v2.0.13 PHP + WP 4.6+ Updated Jul 24, 2017
ajax-searchgoogle-style-searchsearchtaxonomy-searchwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACME Amazing Search Safe to Use in 2026?

Generally Safe

Score 85/100

ACME Amazing Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'acme-amazing-search' v2.0.13 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query handling, exclusively using prepared statements and has no recorded vulnerability history, suggesting a generally stable and secure codebase. The absence of external HTTP requests and critical taint flows is also reassuring.

However, significant concerns arise from its attack surface and a lack of robust access controls. The presence of one unprotected AJAX handler is a direct entry point that could be exploited if it handles user-supplied data without proper sanitization or authorization. Furthermore, the complete absence of nonce checks and capability checks across its entry points indicates a broader systemic weakness in securing actions performed by the plugin.

While the vulnerability history is clean, this should not lead to complacency given the identified code-level risks. The unescaped output percentage is also a notable concern, potentially leading to cross-site scripting (XSS) vulnerabilities. The overall assessment is that while the plugin has some good foundational security practices, the unprotected AJAX handler and the lack of security checks create exploitable weaknesses that need immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks
  • Missing capability checks
  • Low output escaping percentage
Vulnerabilities
None known

ACME Amazing Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ACME Amazing Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
89
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

13% escaped102 total outputs
Attack Surface
1 unprotected

ACME Amazing Search Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_do_cacheincludes\class-acme-amazing-search.php:199

Shortcodes 1

[aas] public\partials\acme-amazing-search-public-shortcodes.php:39
WordPress Hooks 16
actionplugins_loadedincludes\class-acme-amazing-search.php:153
actionadmin_enqueue_stylesincludes\class-acme-amazing-search.php:168
actionadmin_enqueue_scriptsincludes\class-acme-amazing-search.php:169
actionadmin_menuincludes\class-acme-amazing-search.php:175
actionadmin_initincludes\class-acme-amazing-search.php:186
filteraas_plugin_dataincludes\class-acme-amazing-search.php:190
actionsave_postincludes\class-acme-amazing-search.php:201
actionupdate_optionsincludes\class-acme-amazing-search.php:202
filtercache_info_htmlincludes\class-acme-amazing-search.php:203
actionaas_cron_cacheincludes\class-acme-amazing-search.php:204
actionadmin_initincludes\class-acme-amazing-search.php:205
actionwp_enqueue_scriptsincludes\class-acme-amazing-search.php:222
actionwp_enqueue_scriptsincludes\class-acme-amazing-search.php:223
actionACME_AJAX_do_searchincludes\class-acme-amazing-search.php:225
actionACME_AJAX_nopriv_do_searchincludes\class-acme-amazing-search.php:227
actionwp_headincludes\class-acme-amazing-search.php:229

Scheduled Events 1

aas_cron_cache
Maintenance & Trust

ACME Amazing Search Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.0
Last updatedJul 24, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

ACME Amazing Search Developer Profile

acmemediakits

3 plugins · 430 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACME Amazing Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acme-amazing-search/css/acme-amazing-search-admin.css/wp-content/plugins/acme-amazing-search/js/acme-amazing-search-admin.js
Script Paths
/wp-content/plugins/acme-amazing-search/js/acme-amazing-search-admin.js
Version Parameters
acme-amazing-search-admin.css?ver=acme-amazing-search-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- BEGIN ACME AMAZING SEARCH SHORTCODE --><!-- END ACME AMAZING SEARCH SHORTCODE -->
Data Attributes
data-ajax-urldata-search-results-limit
JS Globals
aas_search_params
Shortcode Output
<div class="aas-search-form-wrapper"><input type="text" class="aas-search-input" placeholder="Search..." /><button class="aas-search-button">Search</button><div class="aas-search-results"></div>
FAQ

Frequently Asked Questions about ACME Amazing Search