
i-Search – Advanced Live Search Security & Risk Analysis
wordpress.org/plugins/i-searchLive search suggestions for all post types. Search everywhere, include almost everything in the search. WooCommerce compatible.
Is i-Search – Advanced Live Search Safe to Use in 2026?
Generally Safe
Score 85/100i-Search – Advanced Live Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The i-search plugin v1.2.0 exhibits a mixed security posture. While it shows strengths in avoiding dangerous functions and file operations, and a good proportion of SQL queries utilize prepared statements, significant concerns exist regarding its entry points and output sanitization. The plugin has a notable number of AJAX handlers (19) with a substantial portion (8) lacking proper authentication checks. This directly creates a wider attack surface vulnerable to unauthorized access and manipulation. Furthermore, the taint analysis reveals critical flows with unsanitized paths, indicating potential for injection vulnerabilities. The output escaping is also a weakness, with only 39% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS) attacks. The absence of any recorded CVEs is positive, suggesting a history of responsible development or a lack of targeted exploitation so far, but this should not be relied upon given the identified code-level weaknesses. The plugin would benefit from robust input validation and output escaping across all entry points, particularly the unprotected AJAX handlers, to mitigate identified risks.
Key Concerns
- Unprotected AJAX handlers
- Critical taint flows with unsanitized paths
- Low percentage of properly escaped output
- Bundled libraries (Select2)
i-Search – Advanced Live Search Security Vulnerabilities
i-Search – Advanced Live Search Release Timeline
i-Search – Advanced Live Search Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
i-Search – Advanced Live Search Attack Surface
AJAX Handlers 19
Shortcodes 1
WordPress Hooks 43
Maintenance & Trust
i-Search – Advanced Live Search Maintenance & Trust
Maintenance Signals
Community Trust
i-Search – Advanced Live Search Alternatives
Super Ajax Search
ajax-searchwp
Feature-rich live search with thumbnails, smart excerpts, result grouping, and category filtering.
WDV Ajax Search
wdv-ajax-search
With this plugin you can create different search forms for different post types and put their shortcode on the corresponding page.
Ajax Search Lite – Live Search & Filter
ajax-search-lite
The Best Ajax Live Search and Filter for WordPress. Live suggestions, Custom Post types, Custom fields, Categories, WooCommerce & Elementor support
Advanced Woo Search – Product Search for WooCommerce
advanced-woo-search
Advanced WooCommerce product search plugin. Search inside any product field. Support for both AJAX search and search results page.
Advanced Product Search For WooCommerce
advanced-product-search-for-woo
Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.
i-Search – Advanced Live Search Developer Profile
1 plugin · 10 total installs
How We Detect i-Search – Advanced Live Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/i-search/front/css/i-search-style.css/wp-content/plugins/i-search/front/js/i-search-frontend.js/wp-content/plugins/i-search/front/js/jquery.livequery.min.js/wp-content/plugins/i-search/front/js/waypoints.min.js/wp-content/plugins/i-search/front/js/jquery.magnific-popup.min.js/wp-content/plugins/i-search/front/js/i-search-custom.js/wp-content/plugins/i-search/front/js/i-search-frontend.js/wp-content/plugins/i-search/front/js/jquery.livequery.min.js/wp-content/plugins/i-search/front/js/waypoints.min.js/wp-content/plugins/i-search/front/js/jquery.magnific-popup.min.js/wp-content/plugins/i-search/front/js/i-search-custom.jsi-search/style.css?ver=i-search/frontend.js?ver=HTML / DOM Fingerprints
isrc_ago<!-- i-Search Dashboard widget class --><!-- This file is loaded only in the dashboard screen in the admin area --><!-- Constructor --><!-- is logging enabled? we show only logging data in widget. -->+3 moredata-id="isrc-opt-page"data-tab="general"window.i_search_optswindow.i_search_data[isearch_live_search]