
Combined Search Security & Risk Analysis
wordpress.org/plugins/combined-searchForked from the popular WordPress Search Everything plugin, Combined Search allows you to search all available content types on your web site.
Is Combined Search Safe to Use in 2026?
Generally Safe
Score 85/100Combined Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "combined-search" plugin v1.0 exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. It also demonstrates good practice by using prepared statements for all SQL queries, which significantly mitigates SQL injection risks. Furthermore, the absence of any recorded vulnerabilities in its history suggests a history of stable and potentially secure development.
However, the static analysis reveals concerning practices. The presence of the `create_function` function is a significant red flag, as it is deprecated and can be a source of serious security vulnerabilities if not handled with extreme care and input validation. More critically, the analysis indicates that 0% of outputs are properly escaped, exposing the plugin to Cross-Site Scripting (XSS) vulnerabilities. While no taint flows were identified, the lack of output escaping means that user-supplied data could be injected into the output without sanitization, leading to potential XSS attacks. The absence of capability checks for entry points, though the attack surface is currently zero, is a weakness that could become exploitable if functionality is added without proper security considerations.
Key Concerns
- Uses deprecated and dangerous 'create_function'
- No output escaping for any outputs
- No capability checks on entry points
Combined Search Security Vulnerabilities
Combined Search Release Timeline
Combined Search Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Combined Search Attack Surface
WordPress Hooks 21
Maintenance & Trust
Combined Search Maintenance & Trust
Maintenance Signals
Community Trust
Combined Search Alternatives
Search Everything
search-everything
Search Everything increases WordPress' default search functionality in three easy steps.
WP Extended Search
wp-extended-search
Extend search functionality to search in selected post meta, taxonomies, post types, and all authors.
EchBay Search Everything
echbay-search-everything
Search Everything increases WordPress' default search functionality in three easy steps.
Advance Product Search- Voice & Ajax Search for WooCommerce
th-advance-product-search
Advanced Product Search boosts your store search with instant AJAX results, live suggestions, and smart category filtering, helping customers find pro …
GA Admin Taxonomy Search
ga-admin-taxonomy-search
Make it easy to search/filter items in your admin categories meta box.
Combined Search Developer Profile
1 plugin · 10 total installs
How We Detect Combined Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/combined-search/assets/dist/css/admin.min.csscombined-search/assets/dist/css/admin.min.css?ver=