
Super Search – Custom Post Types Security & Risk Analysis
wordpress.org/plugins/eps-super-searchSuper Search is a customizable widget which allows you to create search forms for custom post types.
Is Super Search – Custom Post Types Safe to Use in 2026?
Generally Safe
Score 85/100Super Search – Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eps-super-search" v1.0.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface with no unprotected entry points. Furthermore, all SQL queries are properly handled with prepared statements, and there are no file operations or external HTTP requests, all of which are strong security indicators. However, the presence of one instance of the `create_function` dangerous function is a significant concern, as it can be exploited for code execution. The 57% rate of properly escaped output, while not critically low, suggests a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled. The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign. This suggests that, despite the code-level risks, the plugin has not yet been publicly exploited or discovered to have significant vulnerabilities. The absence of any taint analysis results is also noteworthy, though this could simply mean no such flows were detected by the tool rather than a guarantee of their absence. In conclusion, while the plugin has a minimal attack surface and good practices in areas like SQL handling, the use of `create_function` and a less than perfect output escaping rate present tangible risks that should be addressed.
Key Concerns
- Use of dangerous function: create_function
- Incomplete output escaping (57% proper)
Super Search – Custom Post Types Security Vulnerabilities
Super Search – Custom Post Types Code Analysis
Dangerous Functions Found
Output Escaping
Super Search – Custom Post Types Attack Surface
WordPress Hooks 4
Maintenance & Trust
Super Search – Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Super Search – Custom Post Types Alternatives
Search Widget Post Types for Elementor
search-widget-post-types-for-elementor
Adds an option to make Elementor's search widget only search for a specific post type such as WooCommerce products or custom post types.
Category Wise Search
category-wise-search
Category Wise Search Widget plugin.You have option search specific category content.
Attribute Dropdowns
attribute-dropdowns
Displays multiple product attributes as drop-down selects with a search button.
gee Search Plus, improved WordPress search
gsearch-plus
Extends WordPress search engine to taxonomies, custom fields and media, sorts results by relevance or date, and more. Simple and clean!
Woo AJAX Search
woo-ajax-search
Woo AJAX search is a product searching plugins for WooCommerce with product category.
Super Search – Custom Post Types Developer Profile
3 plugins · 220 total installs
How We Detect Super Search – Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eps-super-search/templates/admin.php/wp-content/plugins/eps-super-search/templates/widget.phpHTML / DOM Fingerprints
EPS_Super_Search_Widgetdata-posttypejQuery