AI Search – Intelligent Search for WooCommerce and WordPress Security & Risk Analysis

wordpress.org/plugins/ai-search

Replaces the default WordPress search with an AI-powered semantic search system. Perfect for WooCommerce stores and eCommerce sites. ---

80 active installs v1.22.0 PHP 8.0+ WP + Updated Mar 2, 2026
aiecommercesearchsemantic-searchwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Search – Intelligent Search for WooCommerce and WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

AI Search – Intelligent Search for WooCommerce and WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "ai-search" v1.22.0 plugin exhibits a generally positive security posture, with strong adherence to secure coding practices in several key areas. The high percentage of prepared statements for SQL queries and properly escaped output demonstrates a good understanding of preventing common vulnerabilities like SQL injection and XSS. The plugin also includes a significant number of nonce and capability checks, indicating an effort to control access to its functionalities. Furthermore, the complete absence of known CVEs, both historical and current, is a significant strength, suggesting consistent security focus from the developers.

However, there are notable concerns that temper this otherwise strong assessment. The presence of 8 AJAX handlers, with 2 of them lacking authentication checks, presents a clear attack vector. This means that any user, authenticated or not, could potentially trigger these handlers, leading to unexpected behavior or information disclosure depending on their functionality. While the taint analysis found no critical or high severity unsanitized paths, the single identified flow with an unsanitized path, even if categorized as lower severity or not critical, warrants attention as it represents a potential, albeit likely minor, risk. The external HTTP requests, while not inherently a vulnerability, increase the plugin's external dependencies and potential for supply chain attacks if the target endpoints are compromised.

In conclusion, "ai-search" v1.22.0 is a plugin that largely follows secure coding principles, particularly regarding data handling and access control. Its vulnerability history is clean, which is highly commendable. The primary weakness lies in the unprotected AJAX endpoints, which represent a tangible and actionable security risk. Addressing these unprotected entry points should be the immediate priority for the developers to further solidify the plugin's security.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
Vulnerabilities
None known

AI Search – Intelligent Search for WooCommerce and WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AI Search – Intelligent Search for WooCommerce and WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
14 prepared
Unescaped Output
48
230 escaped
Nonce Checks
17
Capability Checks
20
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

93% prepared15 total queries

Output Escaping

83% escaped278 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

14 flows1 with unsanitized paths
display_wizard_page (admin\class-setup-wizard.php:83)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

AI Search – Intelligent Search for WooCommerce and WordPress Attack Surface

Entry Points8
Unprotected2

AJAX Handlers 8

authwp_ajax_ai_search_validate_tokenadmin\class-admin-manager.php:81
authwp_ajax_ai_search_get_taxonomiesadmin\class-admin-manager.php:82
authwp_ajax_ai_search_get_termsadmin\class-admin-manager.php:83
authwp_ajax_ai_search_regenerate_embeddingadmin\class-post-meta-box.php:19
authwp_ajax_ai_search_dismiss_wizardadmin\class-setup-wizard.php:72
authwp_ajax_ai_search_clear_feedbackai-search.php:168
noprivwp_ajax_ai_search_clear_feedbackai-search.php:169
authwp_ajax_ai_search_update_thresholdai-search.php:170
WordPress Hooks 28
actionadmin_menuadmin\class-admin-manager.php:60
actionadmin_noticesadmin\class-admin-manager.php:61
actionadmin_noticesadmin\class-admin-manager.php:62
actionadmin_enqueue_scriptsadmin\class-admin-manager.php:63
actionadmin_enqueue_scriptsadmin\class-admin-manager.php:64
actionadmin_headadmin\class-admin-manager.php:65
filterparent_fileadmin\class-admin-manager.php:66
filtersubmenu_fileadmin\class-admin-manager.php:67
actionadmin_post_ai_search_generate_embeddingsadmin\class-admin-manager.php:70
actionadmin_post_ai_search_clear_cacheadmin\class-admin-manager.php:71
actionadmin_post_ai_search_clear_cache_filteredadmin\class-admin-manager.php:72
actionadmin_post_ai_search_validate_tokenadmin\class-admin-manager.php:73
actionadmin_post_ai_search_save_custom_fieldsadmin\class-admin-manager.php:74
actionadmin_post_ai_search_save_woocommerce_fieldsadmin\class-admin-manager.php:75
actionadmin_post_ai_search_refresh_quotaadmin\class-admin-manager.php:76
actionadmin_post_ai_search_complete_setupadmin\class-admin-manager.php:77
actionadmin_post_ai_search_reconnect_serviceadmin\class-admin-manager.php:78
actionadd_meta_boxesadmin\class-post-meta-box.php:18
actionadmin_enqueue_scriptsadmin\class-post-meta-box.php:20
actioninitai-search.php:150
actiontransition_post_statusai-search.php:154
filterposts_resultsai-search.php:155
filterpost_classai-search.php:158
filterthe_titleai-search.php:161
actionwp_headai-search.php:162
actionwp_footerai-search.php:165
actionadmin_initai-search.php:1519
actionrest_api_initincludes\class-rest-api.php:26
Maintenance & Trust

AI Search – Intelligent Search for WooCommerce and WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 2, 2026
PHP min version8.0
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs80
Developer Profile

AI Search – Intelligent Search for WooCommerce and WordPress Developer Profile

Samuel Silva

6 plugins · 2K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Search – Intelligent Search for WooCommerce and WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-search/assets/css/ai-search-frontend.css/wp-content/plugins/ai-search/assets/js/ai-search-frontend.js
Script Paths
/wp-content/plugins/ai-search/assets/js/ai-search-frontend.js
Version Parameters
ai-search/assets/css/ai-search-frontend.css?ver=ai-search/assets/js/ai-search-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ai-search-badge
Data Attributes
data-ai-search-threshold
JS Globals
ai_search_frontend_params
REST Endpoints
/wp-json/ai-search/v1/search
FAQ

Frequently Asked Questions about AI Search – Intelligent Search for WooCommerce and WordPress