Highlight Search Terms Security & Risk Analysis

wordpress.org/plugins/highlight-search-terms

Very lightweight (vanilla) Javascript that wraps search terms in an HTML5 mark tag within WordPress search results.

7K active installs v1.8.3 PHP 5.6+ WP 3.7+ Updated Apr 4, 2024
highlighthilitemarksearchsearch-terms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Highlight Search Terms Safe to Use in 2026?

Generally Safe

Score 92/100

Highlight Search Terms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "highlight-search-terms" v1.8.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin has no recorded vulnerability history, indicating a consistent track record of security. The attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper security checks. This demonstrates a commitment to secure coding practices and a minimal threat profile.

While the static analysis reveals no immediate threats, the complete lack of logged vulnerabilities and the minimal attack surface could also be interpreted as a sign of limited functionality or infrequent updates, which can sometimes mask latent issues. However, based solely on the provided data, the plugin appears to be secure and well-maintained. There are no specific risks identified in the code analysis or taint flows. The vulnerability history, being entirely empty, further reinforces this positive assessment. In conclusion, the plugin is assessed as having a very good security rating, with no current evidence of exploitable vulnerabilities or insecure coding practices.

Vulnerabilities
None known

Highlight Search Terms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Highlight Search Terms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Highlight Search Terms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterhlst_input_get_argsinc\search-filter-pro.php:10
filterhlst_selectorsinc\search-filter-pro.php:23
filterhlst_selectorsinc\woocommerce.php:10
Maintenance & Trust

Highlight Search Terms Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 4, 2024
PHP min version5.6
Downloads178K

Community Trust

Rating100/100
Number of ratings40
Active installs7K
Developer Profile

Highlight Search Terms Developer Profile

Rolf Allard van Hagen

8 plugins · 111K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
293 days
View full developer profile
Detection Fingerprints

How We Detect Highlight Search Terms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/highlight-search-terms/js/mark.min.js/wp-content/plugins/highlight-search-terms/js/mark.js
Script Paths
/wp-content/plugins/highlight-search-terms/js/mark.min.js/wp-content/plugins/highlight-search-terms/js/mark.js
Version Parameters
highlight-search-terms/js/mark.min.js?ver=highlight-search-terms/js/mark.js?ver=

HTML / DOM Fingerprints

CSS Classes
hiliteterm-0term-1term-2term-3term-4term-5term-6+3 more
HTML Comments
Highlight Search Terms 1.8.3 ( RavanH - http://status301.net/wordpress-plugins/highlight-search-terms/ )
JS Globals
Mark
FAQ

Frequently Asked Questions about Highlight Search Terms