
HeyDay – Search More Security & Risk Analysis
wordpress.org/plugins/heyday-searchBoost engagement and conversions by keeping users on your site with HeyDay Search More’s enhanced search suggestions and real-time product discovery.
Is HeyDay – Search More Safe to Use in 2026?
Generally Safe
Score 92/100HeyDay – Search More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The heyday-search plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query sanitation, exclusively using prepared statements, and has a high rate of properly escaped output. The absence of known CVEs and historical vulnerabilities is a significant strength, suggesting a generally stable and well-maintained codebase. However, the static analysis reveals critical security concerns primarily related to its attack surface. The presence of one unprotected REST API route represents a direct entry point for potential malicious activity without any authentication or permission checks. Furthermore, the lack of nonce checks on any of its entry points, combined with zero capability checks, exacerbates this risk, making it easier for unauthenticated or low-privileged users to trigger unintended actions. The taint analysis also shows flows with unsanitized paths, although these are not flagged as critical or high severity, they still warrant attention in conjunction with the exposed entry points. The plugin's reliance on external HTTP requests, while not inherently a vulnerability, increases its potential attack surface and dependency on external services. In conclusion, while the plugin is free from known vulnerabilities and uses good practices for database interactions and output handling, the unprotected REST API route and the absence of robust authorization mechanisms present a notable security risk that should be addressed.
Key Concerns
- Unprotected REST API route
- No nonce checks on entry points
- No capability checks on entry points
- Taint flows with unsanitized paths
HeyDay – Search More Security Vulnerabilities
HeyDay – Search More Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
HeyDay – Search More Attack Surface
REST API Routes 1
WordPress Hooks 9
Maintenance & Trust
HeyDay – Search More Maintenance & Trust
Maintenance Signals
Community Trust
HeyDay – Search More Alternatives
SearchIQ – The Search Solution
searchiq
Our FREE plugin makes your website’s search fast and more relevant. searchIQ helps you to manage content more effectively with real-time analytics.
Audible Site Search
audible-site-search
Audible Site Search adds voice-powered search and AJAX search suggestions to your WordPress site.
Yext AI Search
yext-ai-search
Add the world's best search experience to your website in minutes.
Yext Answers Site Search
yext-answers
This plugin is no longer being maintained. If you are looking to add Answers to your Wordpress site, please use our new plugin: https://wordpress.
SearchPlus
searchplus
Upgrades you search box to a fast and modern navigation utility.
HeyDay – Search More Developer Profile
1 plugin · 0 total installs
How We Detect HeyDay – Search More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/heyday-search/includes/install.php/wp-content/plugins/heyday-search/includes/feed.php/wp-content/plugins/heyday-search/includes/settings-page.phphttps://cdn.heyday.io/cstmst/heyDayMain.js