
Dragonfly – Advanced Live Search Security & Risk Analysis
wordpress.org/plugins/dragonflySearch Any Post Type Or Taxonomy
Is Dragonfly – Advanced Live Search Safe to Use in 2026?
Generally Safe
Score 100/100Dragonfly – Advanced Live Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dragonfly' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, making no file operations or external HTTP requests, and using prepared statements for all SQL queries. The presence of a nonce check is also a positive indicator. However, several significant concerns emerge from the static analysis. The plugin has a total of 3 entry points, with 1 REST API route lacking permission callbacks, making it an unprotected entry point accessible to unauthenticated users. Furthermore, only 56% of output is properly escaped, indicating a risk of cross-site scripting (XSS) vulnerabilities in nearly half of the output operations. The absence of capability checks on any entry points is a major weakness, as it means that actions intended for administrators or specific user roles could be performed by any user. The vulnerability history is clean, with no known CVEs, which is a strong positive. This suggests the plugin has historically been secure or has not been a target for exploit development. Despite the clean history, the identified code analysis weaknesses, particularly the unprotected REST API route and widespread insufficient output escaping, present tangible security risks that should be addressed.
Key Concerns
- Unprotected REST API route
- Insufficient output escaping
- No capability checks on entry points
Dragonfly – Advanced Live Search Security Vulnerabilities
Dragonfly – Advanced Live Search Code Analysis
Output Escaping
Dragonfly – Advanced Live Search Attack Surface
AJAX Handlers 1
REST API Routes 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Dragonfly – Advanced Live Search Maintenance & Trust
Maintenance Signals
Community Trust
Dragonfly – Advanced Live Search Alternatives
Advanced Product Search For WooCommerce
advanced-product-search-for-woo
Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.
WPSOLR Search — WordPress Search Plugin
wpsolr-free
Enterprise WordPress search plugin. Post types Search, WooCommerce Search, Live Search, Filters, Facets, Recommendations.
Ajax Product Search for WooCommerce (ProSearch)
modern-product-search-for-woocommerce
Smart, fast, and accurate Ajax Product Search for WooCommerce with live results, fuzzy matching, and instant product suggestions.
DooSearch – Ajax Search & Filters for WooCommerce
doosearch-ajax-search-for-woo
A blazing-fast WooCommerce product search plugin with AJAX and live filters to boost conversions.
FtlCommerce – Instant Product Search
ftlcommerce-instant-product-search
Lightning-fast, client-side fuzzy search for WooCommerce products. Zero server delays, instant results, advanced filtering.
Dragonfly – Advanced Live Search Developer Profile
1 plugin · 0 total installs
How We Detect Dragonfly – Advanced Live Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dragonfly/dist/admin.bundle.js/wp-content/plugins/dragonfly/dist/admin.bundle.css/wp-content/plugins/dragonfly/dist/public.bundle.css/wp-content/plugins/dragonfly/dist/public.bundle.js/wp-content/plugins/dragonfly/dist/admin.bundle.js/wp-content/plugins/dragonfly/dist/public.bundle.jsdragonfly/dist/public.bundle.js?ver=1.0HTML / DOM Fingerprints
dragonflySettings/wp-json/8webit/v1/dragonfly/[dragonfly]