
hiWeb Soft Search Security & Risk Analysis
wordpress.org/plugins/hiweb-soft-searchSoft search. Analyzes the search query selects the most similar posts, sorted by relevance. Мягкий поиск. Анализирует поисковый запрос, подбирает пост …
Is hiWeb Soft Search Safe to Use in 2026?
Generally Safe
Score 85/100hiWeb Soft Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hiweb-soft-search plugin v2.0.0.0 exhibits a mixed security posture. On one hand, it avoids the use of dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests. The absence of known historical vulnerabilities is also a positive sign. However, significant concerns arise from the static analysis. The plugin has a single entry point, an AJAX handler, which completely lacks authentication checks. Furthermore, none of the 15 observed output operations are properly escaped, creating a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flaws, did identify two flows with unsanitized paths, which, in conjunction with the unescaped output, could be exploited. The lack of any capability checks or nonce verification on the AJAX handler further exacerbates these risks, as it can be triggered by any user, including unauthenticated ones, and potentially lead to the execution of malicious scripts.
Key Concerns
- AJAX handler without authentication check
- Outputs not properly escaped
- Flows with unsanitized paths
- No nonce checks
- No capability checks
hiWeb Soft Search Security Vulnerabilities
hiWeb Soft Search Code Analysis
Output Escaping
Data Flow Analysis
hiWeb Soft Search Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
hiWeb Soft Search Maintenance & Trust
Maintenance Signals
Community Trust
hiWeb Soft Search Alternatives
Query Filter
query-filter
Advanced taxonomy and Custom Fields CPT filtering plugin.
DITS Lost Search Query
dits-lost-search-query
Tracks lost search queries that return no results to help improve content and SEO. Lightweight and works automatically.
Filter Search Page
filter-search-page
This plugin will help you to filter the search page results by category and post type.
Inject Query Posts
inject-query-posts
Facilitates injecting an array of posts into a WP query object as if queried. Particularly useful to allow use of standard template tags.
Remove Pages From Search
remove-pages-from-search
Tired of search for an one-click solutions for your search results? This plugin will exclude everything except posts from your website's search r …
hiWeb Soft Search Developer Profile
9 plugins · 100 total installs
How We Detect hiWeb Soft Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hiweb-soft-search/css/backend.css/wp-content/plugins/hiweb-soft-search/css/admin.css/wp-content/plugins/hiweb-soft-search/js/hw-search-tool.js/wp-content/plugins/hiweb-soft-search/js/admin.js/wp-content/plugins/hiweb-soft-search/js/hw-search-tool.js/wp-content/plugins/hiweb-soft-search/js/admin.jsHTML / DOM Fingerprints
hiWeb Search index dataHIWEB_SEARCH_META_NAMEHIWEB_SEARCH_URL_CSSHIWEB_SEARCH_URL_JSHIWEB_SEARCH_QUERY_INJECTHIWEB_SEARCH_QUERY_INJECT_METHODhiweb_search_disallow_post_type+2 more