
Energy Search Security & Risk Analysis
wordpress.org/plugins/energy-searchA Pokemon TCG plugin for Wordpress!
Is Energy Search Safe to Use in 2026?
Generally Safe
Score 85/100Energy Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "energy-search" plugin version 0.3 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a positive indicator. The plugin demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. However, a significant concern lies in the output escaping. With 102 total outputs and only 41% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the lack of nonce checks across any of its entry points (AJAX handlers, shortcodes) presents an opportunity for Cross-Site Request Forgery (CSRF) attacks, especially considering the presence of shortcodes as potential interaction points. While capability checks are present for some operations, the overall lack of comprehensive protection on entry points is a notable weakness. The bundled Guzzle library, while not explicitly flagged as outdated, warrants attention as bundled libraries can introduce vulnerabilities if not maintained.
Key Concerns
- Low percentage of properly escaped output
- Lack of nonce checks on entry points
- Bundled library Guzzle
Energy Search Security Vulnerabilities
Energy Search Code Analysis
Bundled Libraries
Output Escaping
Energy Search Attack Surface
Shortcodes 6
WordPress Hooks 8
Maintenance & Trust
Energy Search Maintenance & Trust
Maintenance Signals
Community Trust
Energy Search Alternatives
TCG Card Links
tcg-card-links
The goal of this Plug-in is to provide an instantaneous way for you to turn all Magic: the Gathering card names within your blog posts into card infor …
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
Nginx Cache
nginx-cache
Purge the Nginx cache (FastCGI, Proxy, uWSGI) automatically when content changes or manually within WordPress.
Cleavr Clear Cache
cleavr-clear-cache
Manage NGINX FastCGI cache for Cleavr sites. Add a clear cache hook to clear cache with one click or automatically when content updates.
Magic the Gathering Card Tooltips
magic-the-gathering-card-tooltips
Easily transform Magic the Gathering card names into links that show the card image in a tooltip when hovering over them. You can also quickly create …
Energy Search Developer Profile
1 plugin · 10 total installs
How We Detect Energy Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[es_search_page][es_card_page][es_sets_page][es_search_box]