
WP Fast Total Search – The Power of Indexed Search Security & Risk Analysis
wordpress.org/plugins/fulltext-searchExtends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
Is WP Fast Total Search – The Power of Indexed Search Safe to Use in 2026?
Generally Safe
Score 94/100WP Fast Total Search – The Power of Indexed Search has a strong security track record. Known vulnerabilities have been patched promptly.
The "fulltext-search" plugin v1.79.274 exhibits a concerning security posture, despite some positive indicators. While the plugin largely utilizes prepared statements for SQL queries and performs proper output escaping, a significant portion of its attack surface remains unprotected. A substantial number of AJAX handlers and REST API routes lack authentication and authorization checks, presenting a direct path for unauthorized actions. The presence of dangerous functions like 'unserialize' and 'preg_replace' with the 'e' modifier, coupled with a history of 8 known CVEs, including a high-severity vulnerability, raises significant red flags. The common vulnerability types (Missing Authorization, XSS, CSRF) in its history suggest recurring weaknesses in input validation and access control. While there are currently no unpatched vulnerabilities, the plugin's historical pattern and the static analysis findings indicate a strong potential for future security issues if these fundamental weaknesses are not addressed.
Key Concerns
- 18 unprotected entry points (AJAX, REST API)
- 16 AJAX handlers without auth checks
- 2 REST API routes without permission callbacks
- Vulnerability history: 1 high severity CVE
- Vulnerability history: 7 medium severity CVEs
- Dangerous function: unserialize
- Dangerous function: preg_replace(/e)
- Taint analysis: 2 flows with unsanitized paths
- Bundled library: Select2 (potential outdated version)
WP Fast Total Search – The Power of Indexed Search Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
WP Fast Total Search <= 1.79.270 - Cross-Site Request Forgery
WP Fast Total Search <= 1.79.262 - Missing Authorization
WP Fast Total Search <= 1.78.258 - Missing Authorization
WP Fast Total Search <= 1.78.258 - Cross-Site Request Forgery
WP Fast Total Search <= 1.68.232 - Unauthenticated Stored Cross-Site Scripting
WP Fast Total Search <= 1.69.234 - Cross-Site Request Forgery
WP Fast Total Search <= 1.68.232 - Missing Authorization
WP Fast Total Search <= 1.59.211 - Authenticated (Contributor+) Stored Cross-Site Scripting via WPFTS Live Search Widget
WP Fast Total Search – The Power of Indexed Search Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Fast Total Search – The Power of Indexed Search Attack Surface
AJAX Handlers 19
REST API Routes 2
Shortcodes 1
WordPress Hooks 62
Scheduled Events 2
Maintenance & Trust
WP Fast Total Search – The Power of Indexed Search Maintenance & Trust
Maintenance Signals
Community Trust
WP Fast Total Search – The Power of Indexed Search Alternatives
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
Better Search – Relevant search results for WordPress
better-search
Better Search replaces the default WordPress search with a better search engine that gives contextual results sorted by relevance.
Swiftype Site Search Plugin for WordPress
swiftype-search
Fast, intelligent, and fully customizable search for your site.
Relevant Search
relevant-search
Relevant Search replaces the default WordPress search with relevant results.
Relevanssi – A Better Search
relevanssi
Relevanssi replaces the default search with a partial-match search that sorts results by relevance. It also indexes comments and shortcode content.
WP Fast Total Search – The Power of Indexed Search Developer Profile
5 plugins · 1K total installs
How We Detect WP Fast Total Search – The Power of Indexed Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fulltext-search/style/wpfts_autocomplete.css/wp-content/plugins/fulltext-search/js/wpfts_frontend.js/wp-content/plugins/fulltext-search/js/wpfts_frontend.jsfulltext-search/style/wpfts_autocomplete.css?ver=fulltext-search/js/wpfts_frontend.js?ver=HTML / DOM Fingerprints
wp-block-post-excerpt__more-linkSORRY, WP CORE DEVELOPERS, you had to think about filter that allow not to