LiveDraft Search & Replace Security & Risk Analysis

wordpress.org/plugins/livedraft-search-replace

High-performance Search and Replace for Block Editor. Features real-time scanning, regex support, and safe, zero-tag rendering.

0 active installs v1.6.3 PHP 7.4+ WP 6.3+ Updated Apr 1, 2026
block-editorfind-and-replacegutenbergsearch-replacetext-editor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LiveDraft Search & Replace Safe to Use in 2026?

Generally Safe

Score 100/100

LiveDraft Search & Replace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The `livedraft-search-replace` plugin, version 1.5.6, demonstrates an exceptionally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or any form of input sanitization issues in the taint analysis is highly commendable. Furthermore, the plugin appears to have no recorded vulnerability history, indicating a commitment to maintaining a secure codebase.

While the static analysis reveals a near-perfect security profile, the complete lack of entry points (AJAX handlers, REST API routes, shortcodes, cron events) and the absence of any capability or nonce checks are noteworthy. This could suggest the plugin is designed to be purely administrative and might rely on WordPress's core user role and permissions system for access control. However, it also means that if any functionality were to be added or discovered later that bypasses these core WordPress mechanisms, it could present a risk. The plugin's security strength lies in its current minimal attack surface and lack of apparent vulnerabilities, but it's important to acknowledge that a lack of checks in place doesn't inherently equate to robustness if future development introduces vulnerabilities.

Vulnerabilities
None known

LiveDraft Search & Replace Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LiveDraft Search & Replace Release Timeline

v1.6.3Current
v1.6.2
v1.6.1
v1.6.0
v1.5.6
v1.5.5
v1.5.0
v1.4.1
v1.4.0
Code Analysis
Analyzed Mar 17, 2026

LiveDraft Search & Replace Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LiveDraft Search & Replace Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionenqueue_block_editor_assetslivedraft-search-replace.php:18
Maintenance & Trust

LiveDraft Search & Replace Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads442

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LiveDraft Search & Replace Developer Profile

Kasuga

8 plugins · 140 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect LiveDraft Search & Replace

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livedraft-search-replace/livedraft-search-replace.js
Script Paths
/wp-content/plugins/livedraft-search-replace/livedraft-search-replace.js

HTML / DOM Fingerprints

JS Globals
ESR_L10N
FAQ

Frequently Asked Questions about LiveDraft Search & Replace