
Admin Global Search Security & Risk Analysis
wordpress.org/plugins/admin-global-searchAdmin Global Search
Is Admin Global Search Safe to Use in 2026?
Generally Safe
Score 85/100Admin Global Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admin-global-search' v1.0.0 plugin exhibits a concerning security posture primarily due to its unprotected entry points. The static analysis reveals two AJAX handlers, both of which lack any authentication or capability checks. This creates a significant attack surface, as any authenticated user, or potentially even unauthenticated users depending on WordPress configurations, could trigger these functions. While the plugin shows strengths in other areas like avoiding dangerous functions and using prepared statements for SQL queries, the absence of basic security measures on its AJAX endpoints is a major vulnerability. The lack of any recorded vulnerability history is positive, suggesting that the developers may not have introduced known exploitable flaws in the past. However, this should not overshadow the immediate risks presented by the unprotected AJAX handlers. The low percentage of properly escaped output is another concern, increasing the risk of cross-site scripting (XSS) vulnerabilities when data is displayed back to users. The plugin's limited functionality and attack surface, combined with the lack of past vulnerabilities, suggest a potentially simple plugin, but the critical oversight in securing its AJAX entry points makes it a target.
Key Concerns
- AJAX handlers without auth/capability checks
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
Admin Global Search Security Vulnerabilities
Admin Global Search Code Analysis
Output Escaping
Admin Global Search Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Admin Global Search Maintenance & Trust
Maintenance Signals
Community Trust
Admin Global Search Alternatives
Better WP-Admin Search
better-wp-admin-search
Add essential search functionality to your WP Admin.
Search Exclude
search-exclude
Hide any post or page from the search results.
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
Search and Replace
search-replace
Search and replace content into pages and posts
Admin Global Search Developer Profile
3 plugins · 60 total installs
How We Detect Admin Global Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-global-search/src/custom.js/wp-content/plugins/admin-global-search/src/style.css/wp-content/plugins/admin-global-search/src/custom.jsadmin-global-search/src/custom.js?ver=admin-global-search/src/style.css?ver=HTML / DOM Fingerprints
WPS_ADMIN_GLOBAL_SEARCH_OBJECT/wp-json/admin-global-search/v1/search