
CloudSearch Security & Risk Analysis
wordpress.org/plugins/cloud-searchCloudSearch is a flexible plugin that allows you to leverage the search index power of Amazon CloudSearch in your WordPress site.
Is CloudSearch Safe to Use in 2026?
Use With Caution
Score 63/100CloudSearch has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "cloud-search" v3.0.0 plugin presents a significant security risk due to a large, unprotected attack surface. All 34 identified AJAX handlers lack authentication checks, making them prime targets for unauthorized actions. While the plugin doesn't appear to have critical or high-severity taint flow issues, the absence of proper authorization on such a vast number of entry points is deeply concerning. The presence of 8 unsanitized path flows, even without a critical severity rating, suggests potential for directory traversal or similar vulnerabilities if further exploited.
The plugin's vulnerability history, featuring one unpatched medium-severity CVE, raises questions about the diligence in addressing past security issues. The fact that the last vulnerability was recorded in the future (2025-10-16) is an anomaly and should be investigated, but assuming it's a data error, a past medium vulnerability indicates a tendency for security flaws to emerge. Coupled with a large number of unprotected AJAX handlers and a single SQL query that does not utilize prepared statements, the plugin's overall security posture is weak.
Despite the concerning lack of authentication on AJAX handlers, the plugin does show some positive signs, such as the presence of nonce and capability checks (though limited) and a reasonable rate of output escaping (58%). The absence of external HTTP requests and a low number of file operations are also positive indicators. However, these strengths are overshadowed by the critical weakness of an exposed attack surface and a history of vulnerabilities. The bundled Guzzle library also requires attention regarding its version and potential known vulnerabilities.
Key Concerns
- 34 AJAX handlers without auth checks
- 1 SQL query without prepared statements
- 8 unsanitized path flows
- 1 unpatched medium CVE
- Bundled library (Guzzle) might be outdated
CloudSearch Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CloudSearch <= 3.0.0 - Cross-Site Request Forgery
CloudSearch Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CloudSearch Attack Surface
AJAX Handlers 34
WordPress Hooks 15
Maintenance & Trust
CloudSearch Maintenance & Trust
Maintenance Signals
Community Trust
CloudSearch Alternatives
DocumentCloud
documentcloud
Embed DocumentCloud resources in WordPress content.
WPAdmin AWS CDN
aws-cdn-by-wpadmin
Setup Amazon Cloudfront CDN for your website. Now with intuitive layout and more flexibility.
Kumori (曇)
kumori
It's a plugin that lets the users upload video files and transcode them on-the-cloud!
Ultimate Media On The Cloud Lite
ultimate-media-on-the-cloud-lite
With Ultimate Media On The Cloud plugin, you can easy migrate/ move and mange wordpress medias on the Cloud Storage Platforms like Amazon S3, Google C …
WP2Cloud
wp2cloud-wordpress-to-cloud
Now WordPress site can store all its content (pages and media) in cloud. This makes site powered by enormous scale and reliability of cloud storage.
CloudSearch Developer Profile
4 plugins · 1K total installs
How We Detect CloudSearch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloud-search/css/cloud-search-main.css/wp-content/plugins/cloud-search/css/cloud-search-admin.css/wp-content/plugins/cloud-search/js/cloud-search-admin.js/wp-content/plugins/cloud-search/js/cloud-search-main.js/wp-content/plugins/cloud-search/js/cloud-search-utils.js/wp-content/plugins/cloud-search/js/cloud-search-main.js/wp-content/plugins/cloud-search/js/cloud-search-utils.js/wp-content/plugins/cloud-search/js/cloud-search-admin.jscloud-search/css/cloud-search-main.css?ver=cloud-search/css/cloud-search-admin.css?ver=cloud-search/js/cloud-search-admin.js?ver=cloud-search/js/cloud-search-main.js?ver=cloud-search/js/cloud-search-utils.js?ver=HTML / DOM Fingerprints
cloud-search-resultscloud-search-filterscloud-search-autocomplete-wrappercloud-search-autocomplete-inputcloud-search-autocomplete-results<!-- CloudSearch plugin. --><!-- CloudSearch admin plugin. -->data-cloudsearch-query-inputdata-cloudsearch-results-containerdata-cloudsearch-filter-containercloudSearchacs_settingsACS/wp-json/cloud-search/v1/search/wp-json/cloud-search/v1/suggest[cloud_search_results][cloud_search_filters][cloud_search_autocomplete]