
Advanced Custom Post Search Security & Risk Analysis
wordpress.org/plugins/advanced-custom-post-searchA useful plugin for creating search forms & results pages for custom post types & taxonomies.
Is Advanced Custom Post Search Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Post Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-custom-post-search" plugin v1.2.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and not making external HTTP requests or performing file operations. The absence of known CVEs and bundled libraries is also a strength. However, several significant concerns are present. The plugin has a notable attack surface with one AJAX handler lacking authentication checks. The presence of the `unserialize` function is a red flag, as it can lead to object injection vulnerabilities if not handled with extreme care. Furthermore, only a small percentage of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis shows a flow with unsanitized paths, which, while not classified as critical or high in this specific instance, still points to potential security weaknesses.
Key Concerns
- AJAX handler without authentication
- Dangerous function: unserialize used
- Low output escaping percentage
- Taint flow with unsanitized paths
Advanced Custom Post Search Security Vulnerabilities
Advanced Custom Post Search Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Advanced Custom Post Search Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Advanced Custom Post Search Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Post Search Alternatives
Custom Search by BestWebSoft – WordPress Custom Search Plugin
custom-search-plugin
Add advanced custom search to your WordPress site. Search custom post types, taxonomies, and custom fields with full control over results.
gee Search Plus, improved WordPress search
gsearch-plus
Extends WordPress search engine to taxonomies, custom fields and media, sorts results by relevance or date, and more. Simple and clean!
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
YITH WooCommerce Ajax Search
yith-woocommerce-ajax-search
YITH WooCommerce Ajax Search allows your users to search products in real time.
Advanced Custom Post Search Developer Profile
1 plugin · 200 total installs
How We Detect Advanced Custom Post Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-post-search/css/acps-admin.css/wp-content/plugins/advanced-custom-post-search/css/acps-frontend.css/wp-content/plugins/advanced-custom-post-search/css/chzn.css/wp-content/plugins/advanced-custom-post-search/js/admin-ajax.js/wp-content/plugins/advanced-custom-post-search/js/chzn.js/wp-content/plugins/advanced-custom-post-search/js/admin-ajax.js/wp-content/plugins/advanced-custom-post-search/js/chzn.jsadvanced-custom-post-search/css/acps-admin.css?ver=advanced-custom-post-search/css/acps-frontend.css?ver=advanced-custom-post-search/css/chzn.css?ver=advanced-custom-post-search/js/admin-ajax.js?ver=advanced-custom-post-search/js/chzn.js?ver=HTML / DOM Fingerprints
data-acps-search-id