
Improved user search in backend Security & Risk Analysis
wordpress.org/plugins/improved-user-search-in-backendImproves the search for users in the backend significantly: Search for first name, last, email and more of users instead of only nicename.
Is Improved user search in backend Safe to Use in 2026?
Generally Safe
Score 85/100Improved user search in backend has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'improved-user-search-in-backend' plugin, version 1.2.6, presents a mixed security posture. While it boasts a zero attack surface for entry points and correctly escapes all identified outputs, indicating a good understanding of frontend security, the static analysis reveals concerning trends in its backend code. Specifically, the plugin utilizes raw SQL queries without prepared statements, a significant security weakness that can lead to SQL injection vulnerabilities if not handled meticulously. Furthermore, the taint analysis highlights two high-severity flows with unsanitized paths, suggesting potential risks where user-supplied input could be processed in a way that compromises application integrity or exposes sensitive data. The plugin's vulnerability history, though only including a single medium-severity Cross-Site Scripting (XSS) vulnerability from 2014 and currently unpatched CVEs, indicates past issues with input sanitization. While the absence of recent vulnerabilities is a positive sign, the identified code signals and taint flows warrant caution, suggesting that ongoing vigilance and potential code refactoring are advisable to maintain a robust security profile.
Key Concerns
- Raw SQL queries without prepared statements
- High severity taint flows with unsanitized paths
- Medium severity CVE history (XSS)
Improved user search in backend Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Improved User Search in Backend <= 1.2.5 - Cross-Site Request Forgery to Cross-Site Scripting
Improved user search in backend Release Timeline
Improved user search in backend Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Improved user search in backend Attack Surface
WordPress Hooks 3
Maintenance & Trust
Improved user search in backend Maintenance & Trust
Maintenance Signals
Community Trust
Improved user search in backend Alternatives
Enhanced Admin User Search
enhanced-admin-user-search
This plugin extends the default WordPress admin user search functionality in the search query.
Extended User Search In WP-Admin
extended-user-search-in-wp-admin
By default WordPress in WP-admin allows users to search only by username or email id.
Better User Search
better-user-search
Better User Search is a must have plugin if you're running WooCommerce. Without it, you're stuck trying to remember every
Enhanced User Search
enhanced-user-search
Effortlessly find users in WordPress! Search by first & last name, username, or email.
User First Name / Full Name Search In WP-admin
full-name-search-in-wp-admin
User First Name / Full Name Search In WP-admin plugin which empowers users search with no hassles.
Improved user search in backend Developer Profile
4 plugins · 210 total installs
How We Detect Improved user search in backend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablename="improved_user_search_in_backend_update"value="true"name="iusib_meta_fields"rows="6"cols="50"name="Save"+1 more