Admin Instant Search Security & Risk Analysis

wordpress.org/plugins/admin-instant-search

Search WooCommerce orders fast without having to wait for the page to load between searches.

0 active installs v1.1.1 PHP 7.4+ WP 6.5+ Updated Aug 6, 2025
admin-instant-searchinstant-order-searchinstant-searchwoocommercewp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin Instant Search Safe to Use in 2026?

Generally Safe

Score 100/100

Admin Instant Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The admin-instant-search plugin version 1.1.1 exhibits a generally strong security posture based on the provided static analysis. It adheres to several key security best practices, including the complete absence of dangerous functions, proper SQL statement preparation, and 100% output escaping. Furthermore, it implements both nonce and capability checks on its entry points, and there are no recorded vulnerabilities or CVEs in its history, indicating a potentially well-maintained codebase. The attack surface, while present with AJAX handlers and REST API routes, appears to be protected by authentication mechanisms, as no unprotected entry points were identified.

However, there are no specific high-risk areas identified from the static analysis. The absence of taint analysis results and recorded vulnerability history, while positive, could also indicate a lack of comprehensive historical security auditing or a very small user base that has not yet encountered or reported issues. The bundled Select2 library, if outdated, could potentially represent a minor risk, though its specific version and known vulnerabilities are not detailed here. Overall, the plugin appears to be developed with security in mind, but further deep dives into the specific implementation of the bundled library and a more extensive vulnerability history review would provide a more complete picture.

Key Concerns

  • Bundled outdated library (Select2)
Vulnerabilities
None known

Admin Instant Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Admin Instant Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
69 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped69 total outputs
Attack Surface

Admin Instant Search Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_admin_instant_search_reindex_allincludes\classes\Backend\Reindexer.php:48

REST API Routes 1

GET/wp-json/admin-instant-search/v1/orders/includes\classes\Backend\API.php:31
WordPress Hooks 13
actionadmin_menuincludes\classes\Backend\Admin.php:47
actionadmin_initincludes\classes\Backend\Admin.php:48
actionadmin_menuincludes\classes\Backend\Admin.php:54
actionadmin_noticesincludes\classes\Backend\Admin.php:64
actionadmin_noticesincludes\classes\Backend\Admin.php:65
actionrest_api_initincludes\classes\Backend\API.php:18
actionadmin_instant_search_background_workerincludes\classes\Backend\Background_Worker.php:30
actioncron_schedulesincludes\classes\Backend\Background_Worker.php:31
actionadmin_enqueue_scriptsincludes\classes\Backend\Enqueue.php:39
actionwoocommerce_thankyouincludes\classes\Backend\Index_Updater.php:27
actionadmin_noticesincludes\classes\Dependency_Loader.php:54
actionwp_enqueue_scriptsincludes\classes\Frontend\Enqueue.php:40
actionwpincludes\classes\Updater.php:40

Scheduled Events 1

admin_instant_search_background_worker
Maintenance & Trust

Admin Instant Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 6, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Admin Instant Search Developer Profile

Poly Plugins

9 plugins · 320 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin Instant Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-instant-search/css/backend/settings.css/wp-content/plugins/admin-instant-search/css/backend/bootstrap-wrapper.min.css/wp-content/plugins/admin-instant-search/css/bootstrap-icons.min.css/wp-content/plugins/admin-instant-search/css/backend/select2.min.css/wp-content/plugins/admin-instant-search/css/backend/sweetalert2.min.css/wp-content/plugins/admin-instant-search/js/backend/dismiss-notices.js/wp-content/plugins/admin-instant-search/js/backend/settings.js/wp-content/plugins/admin-instant-search/js/bootstrap.min.js+4 more
Script Paths
/wp-content/plugins/admin-instant-search/js/backend/dismiss-notices.js/wp-content/plugins/admin-instant-search/js/backend/settings.js/wp-content/plugins/admin-instant-search/js/bootstrap.min.js/wp-content/plugins/admin-instant-search/js/backend/select2.min.js/wp-content/plugins/admin-instant-search/js/backend/sweetalert2.all.min.js/wp-content/plugins/admin-instant-search/js/backend/orders.js
Version Parameters
admin-instant-search/css/backend/settings.css?ver=admin-instant-search/css/backend/bootstrap-wrapper.min.css?ver=admin-instant-search/css/bootstrap-icons.min.css?ver=admin-instant-search/css/backend/select2.min.css?ver=admin-instant-search/css/backend/sweetalert2.min.css?ver=admin-instant-search/js/backend/dismiss-notices.js?ver=admin-instant-search/js/backend/settings.js?ver=admin-instant-search/js/bootstrap.min.js?ver=admin-instant-search/js/backend/select2.min.js?ver=admin-instant-search/js/backend/sweetalert2.all.min.js?ver=admin-instant-search/css/backend/orders.css?ver=admin-instant-search/js/backend/orders.js?ver=

HTML / DOM Fingerprints

CSS Classes
admin-instant-search-dismiss-noticeadmin-instant-search-orders-search-formadmin-instant-search-orders-search-input
HTML Comments
This is a placeholder comment.For security reasons, we are preventing direct access to this file.This script is responsible for handling AJAX requests for the instant search functionality on the WooCommerce orders page.Ensure the 'admin-instant-search-settings' script handle translation using wp_set_script_translations+1 more
Data Attributes
data-search-url
JS Globals
admin_instant_search_object
REST Endpoints
/wp-json/admin-instant-search/v1/search
FAQ

Frequently Asked Questions about Admin Instant Search