
Ivory Search – WordPress Search Plugin Security & Risk Analysis
wordpress.org/plugins/add-search-to-menuAdvanced WordPress custom search plugin. Provides Search Form Customizer, WooCommerce Search, AJAX Search & Live Search support!
Is Ivory Search – WordPress Search Plugin Safe to Use in 2026?
Generally Safe
Score 95/100Ivory Search – WordPress Search Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "add-search-to-menu" plugin, version 5.5.14, exhibits a mixed security posture. While it shows strengths in database query sanitization with 97% prepared statements and a high rate of output escaping (82%), significant concerns arise from its attack surface. A substantial portion of its entry points, specifically 4 out of 5, lack proper authentication checks. This is further compounded by 4 identified flows with unsanitized paths during taint analysis, although no critical or high severity issues were found in this specific analysis. The plugin's vulnerability history is a major red flag, with a total of 11 known medium-severity CVEs, including past instances of Cross-site Scripting, Sensitive Information Exposure, and Missing Authorization. The fact that the last vulnerability was in 2026, while the current version is 5.5.14 (which suggests it might be a future version or the vulnerability data is from a future context, but the principle of past issues remains), highlights a recurring pattern of security weaknesses that have required patching. Despite the current static analysis not revealing critical vulnerabilities, the historical pattern and the unprotected attack surface warrant caution.
Key Concerns
- 4 AJAX handlers without auth checks
- 4 flows with unsanitized paths
- 11 total known CVEs (medium severity)
- Bundled library Freemius v1.0
Ivory Search – WordPress Search Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Ivory Search <= 5.5.13 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters
Ivory Search <= 5.5.12 - Missing Authorization
Ivory Search – WordPress Search Plugin <= 5.5.9 - Authenticated (Admin+) Stored Cross-Site Scripting
Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form
Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation
Ivory Search <= 5.4.6 - Reflected Cross-Site Scripting
Ivory Search <= 5.4 - Multiple Admin+ Stored Cross-Site Scripting
Ivory Search <= 4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ivory Search <= 4.6.6 - Reflected Cross-Site Scripting
Ivory Search <= 4.6 - Reflected Cross Site Scripting
Ivory Search – WordPress Search Plugin <= 4.5.10 - Reflected Cross-Site Scripting
Ivory Search – WordPress Search Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Ivory Search – WordPress Search Plugin Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 50
Maintenance & Trust
Ivory Search – WordPress Search Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Ivory Search – WordPress Search Plugin Alternatives
FiboSearch – Ajax Search for WooCommerce
ajax-search-for-woocommerce
The most popular WooCommerce product search plugin. Gives your users a well-designed advanced AJAX search bar with live search suggestions.
Smart WooCommerce Search
smart-woocommerce-search
Ideal Product Search plugin for WooCommerce shops that enhances users' experience with a live search feature.
Jetpack Search
jetpack-search
Easily add cloud-powered instant search and filters to your website or WooCommerce store with advanced algorithms that boost your search results based …
Advanced Product Search For WooCommerce
advanced-product-search-for-woo
Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.
Magnify – Suggestive Search Plugin
magnify-suggestive-search
Real-time search suggestions that display relevant results as users type. Easy to customize, fast, and responsive on all devices.
Ivory Search – WordPress Search Plugin Developer Profile
3 plugins · 109K total installs
How We Detect Ivory Search – WordPress Search Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-search-to-menu/admin/css/ivory-search-admin.css/wp-content/plugins/add-search-to-menu/admin/js/ivory-search-admin.js/wp-content/plugins/add-search-to-menu/assets/css/is-frontend.css/wp-content/plugins/add-search-to-menu/assets/js/is-frontend.js/wp-content/plugins/add-search-to-menu/assets/js/is-search.js/wp-content/plugins/add-search-to-menu/admin/js/ivory-search-admin.js/wp-content/plugins/add-search-to-menu/assets/js/is-frontend.js/wp-content/plugins/add-search-to-menu/assets/js/is-search.jsadd-search-to-menu/admin/css/ivory-search-admin.css?ver=add-search-to-menu/admin/js/ivory-search-admin.js?ver=add-search-to-menu/assets/css/is-frontend.css?ver=add-search-to-menu/assets/js/is-frontend.js?ver=add-search-to-menu/assets/js/is-search.js?ver=HTML / DOM Fingerprints
is-search-form-containeris-search-submit-buttonis-search-input-field<!-- The main plugin class --><!-- Main Ivory Search Class --><!-- Core singleton class --><!-- Gets the instance of this class -->+16 moredata-is-search-idivory_search_admin_params