
Improved user search in backend Security & Risk Analysis
wordpress.org/plugins/improved-user-search-in-backendImproves the search for users in the backend significantly: Search for first name, last, email and more of users instead of only nicename.
Is Improved user search in backend Safe to Use in 2026?
Generally Safe
Score 85/100Improved user search in backend has a strong security track record. Known vulnerabilities have been patched promptly.
The 'improved-user-search-in-backend' plugin, version 1.2.6, presents a mixed security posture. While it boasts a zero attack surface for entry points and correctly escapes all identified outputs, indicating a good understanding of frontend security, the static analysis reveals concerning trends in its backend code. Specifically, the plugin utilizes raw SQL queries without prepared statements, a significant security weakness that can lead to SQL injection vulnerabilities if not handled meticulously. Furthermore, the taint analysis highlights two high-severity flows with unsanitized paths, suggesting potential risks where user-supplied input could be processed in a way that compromises application integrity or exposes sensitive data. The plugin's vulnerability history, though only including a single medium-severity Cross-Site Scripting (XSS) vulnerability from 2014 and currently unpatched CVEs, indicates past issues with input sanitization. While the absence of recent vulnerabilities is a positive sign, the identified code signals and taint flows warrant caution, suggesting that ongoing vigilance and potential code refactoring are advisable to maintain a robust security profile.
Key Concerns
- Raw SQL queries without prepared statements
- High severity taint flows with unsanitized paths
- Medium severity CVE history (XSS)
Improved user search in backend Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Improved User Search in Backend <= 1.2.5 - Cross-Site Request Forgery to Cross-Site Scripting
Improved user search in backend Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Improved user search in backend Attack Surface
WordPress Hooks 3
Maintenance & Trust
Improved user search in backend Maintenance & Trust
Maintenance Signals
Community Trust
Improved user search in backend Alternatives
Enhanced Admin User Search
enhanced-admin-user-search
This plugin extends the default WordPress admin user search functionality in the search query.
Extended User Search In WP-Admin
extended-user-search-in-wp-admin
By default WordPress in WP-admin allows users to search only by username or email id.
Better User Search
better-user-search
Better User Search is a must have plugin if you're running WooCommerce. Without it, you're stuck trying to remember every
Enhanced User Search
enhanced-user-search
Effortlessly find users in WordPress! Search by first & last name, username, or email.
User First Name / Full Name Search In WP-admin
full-name-search-in-wp-admin
User First Name / Full Name Search In WP-admin plugin which empowers users search with no hassles.
Improved user search in backend Developer Profile
3 plugins · 200 total installs
How We Detect Improved user search in backend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablename="improved_user_search_in_backend_update"value="true"name="iusib_meta_fields"rows="6"cols="50"name="Save"+1 more