
Advanced Plugin Search Security & Risk Analysis
wordpress.org/plugins/advanced-plugin-searchFree yourself from the limitations of the standard plugin search delivered by WordPress core. List plugins that have been updated within the last X mo …
Is Advanced Plugin Search Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Plugin Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The advanced-plugin-search v0.0.2 plugin presents a mixed security posture. On the positive side, it has a very small attack surface with only one AJAX handler and no REST API routes, shortcodes, or cron events. Crucially, the single AJAX handler appears to have capability checks, which is a good practice. The vulnerability history is clean, with no recorded CVEs, suggesting a relatively stable past. However, significant concerns arise from the code analysis. The presence of the `unserialize` function is a major red flag, as it can lead to remote code execution if not handled with extreme care and validation of the serialized data. Furthermore, a high percentage of SQL queries (60%) are not using prepared statements, increasing the risk of SQL injection vulnerabilities. The low rate of proper output escaping (13%) is another critical weakness, opening the door to cross-site scripting (XSS) attacks. The taint analysis also highlights that all analyzed flows have unsanitized paths, which, while not classified as critical or high severity in this instance, indicates a general lack of input sanitization. These code-level weaknesses outweigh the benefits of the limited attack surface and clean history.
Key Concerns
- Unsanitized taint flows detected
- Dangerous unserialize function used
- SQL queries not using prepared statements
- Low percentage of properly escaped output
Advanced Plugin Search Security Vulnerabilities
Advanced Plugin Search Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Plugin Search Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Advanced Plugin Search Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Plugin Search Alternatives
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Simple Shortcode for Google Maps
simple-google-maps-short-code
A simple shortcode for embedding Google Maps in any WordPress post, page or widget.
Master Accordion ( Former WP Awesome FAQ Plugin )
wp-awesome-faq
Best WordPress Accordion Plugin for WordPress. Master Accordion re-branded with lots new features and customization options
Web Directory Free
web-directory-free
Build Directory or Classifieds site in some minutes. The plugin combines flexibility of WordPress and functionality of Directory and Classifieds.
Calculate Prices based on Distance For WooCommerce
calculate-prices-based-on-distance-for-woocommerce
The best WooCommerce Distance Rate Shipping alternative. Secure delivery fee calculation by KM/Mile via Google Maps. Supports Block Checkout & Del …
Advanced Plugin Search Developer Profile
17 plugins · 130 total installs
How We Detect Advanced Plugin Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-plugin-search/js/klick-aps.js/wp-content/plugins/advanced-plugin-search/css/klick-aps.css/wp-content/plugins/advanced-plugin-search/js/klick-aps.jsadvanced-plugin-search/js/klick-aps.js?ver=advanced-plugin-search/css/klick-aps.css?ver=HTML / DOM Fingerprints
klick-logo-and-titleplugin-status-lebeldownloaded-plugin-statusCopyright 2017 klick on it (http://klick-on-it.com)This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+1 moreid='plugin-db_create'id='plugin-filter'name='klick_aps_plugin_data'id='klick_aps_plugin_data'id='aps_create_db'name='aps_create_db'+1 morevar klick_aps_ajax_nonce