
Better Search – Relevant search results for WordPress Security & Risk Analysis
wordpress.org/plugins/better-searchBetter Search replaces the default WordPress search with a better search engine that gives contextual results sorted by relevance.
Is Better Search – Relevant search results for WordPress Safe to Use in 2026?
Mostly Safe
Score 83/100Better Search – Relevant search results for WordPress is generally safe to use. 8 past CVEs were resolved.
The 'better-search' plugin v4.2.4 presents a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface, with no unprotected AJAX handlers or REST API routes identified. The code demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output, along with a substantial number of nonce and capability checks. However, there are concerns regarding the presence of unsanitized paths in taint analysis, although these did not reach critical or high severity in this version. The history of 8 known CVEs, including critical and high severity vulnerabilities, is a significant red flag, even though there are currently no unpatched vulnerabilities. This history suggests a pattern of developing security flaws, potentially related to input sanitization (XSS, SQL injection), authentication bypass, and CSRF, which require diligent attention. The bundled Freemius library, though not analyzed for its version, could also represent a potential risk if it's outdated.
Key Concerns
- History of 8 known CVEs
- Past critical severity CVEs
- Past high severity CVEs
- Flows with unsanitized paths
- SQL queries not using prepared statements
- Bundled Freemius v1.0 library
Better Search – Relevant search results for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Better Search <= 4.2.1 - Authenticated (Author+) Stored Cross-Site Scripting
Better Search <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Better Search <= 3.3.0 - Unauthenticated Stored Cross-Site Scripting
Better Search <= 3.1.0 - Cross-Site Request Forgery
Better Search <= 2.5.2 - Cross-Site Request Forgery Bypass
Better Search <= 2.5.2 - Cross-Site Request Forgery to Settings Import
Better Search < 2.2.3 - SQL Injection
Better Search <= 1.3.4 - Reflected Cross-Site Scripting
Better Search – Relevant search results for WordPress Release Timeline
Better Search – Relevant search results for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Better Search – Relevant search results for WordPress Attack Surface
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
Better Search – Relevant search results for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Better Search – Relevant search results for WordPress Alternatives
Relevanssi – A Better Search
relevanssi
Relevanssi replaces the default search with a partial-match search that sorts results by relevance. It also indexes comments and shortcode content.
WP Fast Total Search – The Power of Indexed Search
fulltext-search
Extends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
Swiftype Site Search Plugin for WordPress
swiftype-search
Fast, intelligent, and fully customizable search for your site.
Relevant Search
relevant-search
Relevant Search replaces the default WordPress search with relevant results.
Fast WordPress Search
fast-wordpress-search
Faster and Relevance WordPress Search result with low resource consuming
Better Search – Relevant search results for WordPress Developer Profile
34 plugins · 79K total installs
How We Detect Better Search – Relevant search results for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-search/includes/css/admin-style.css/wp-content/plugins/better-search/includes/css/admin-frontend-style.css/wp-content/plugins/better-search/includes/js/admin-scripts.js/wp-content/plugins/better-search/includes/images/default-thumb.png/wp-content/plugins/better-search/includes/js/admin-scripts.jsbetter-search/includes/css/admin-style.css?ver=better-search/includes/css/admin-frontend-style.css?ver=better-search/includes/js/admin-scripts.js?ver=HTML / DOM Fingerprints
wz-admin-banner<!-- Better Search Options Page --><!-- Better Search - Addons Section -->data-bsearch-settingdata-bsearch-typedata-bsearch-valueBetterSearchSettings