
Media Search Enhanced Security & Risk Analysis
wordpress.org/plugins/media-search-enhancedSearch through all fields in Media Library.
Is Media Search Enhanced Safe to Use in 2026?
Generally Safe
Score 99/100Media Search Enhanced has a strong security track record. Known vulnerabilities have been patched promptly.
The "media-search-enhanced" plugin v0.9.2 demonstrates some good security practices, notably the exclusive use of prepared statements for all SQL queries and proper output escaping. The static analysis also shows no critical or high severity taint flows, a clean slate for file operations and external HTTP requests. The attack surface is minimal with only one shortcode and no unprotected entry points identified in this analysis.
However, there are significant concerns. The plugin completely lacks nonce checks and capability checks. This means that any authenticated user, regardless of their role, could potentially trigger actions associated with the shortcode. The presence of a past medium severity SQL injection vulnerability, even if currently patched, is a red flag and suggests potential for similar issues if sanitization or input validation is not consistently applied. The fact that a vulnerability was recorded as recently as 2026-01-07 (though likely a typo and meant to be in the past) also warrants attention.
In conclusion, while the plugin has made strides in secure coding for SQL and output handling, the absence of proper authorization and capability checks presents a substantial risk. Coupled with the history of an SQL injection vulnerability, this plugin requires careful monitoring and potentially further security hardening before being considered robustly secure.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Past medium SQL injection vulnerability
Media Search Enhanced Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Media Search Enhanced <= 0.9.1 - Authenticated (Author+) SQL Injection
Media Search Enhanced Code Analysis
SQL Query Safety
Output Escaping
Media Search Enhanced Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Media Search Enhanced Maintenance & Trust
Maintenance Signals
Community Trust
Media Search Enhanced Alternatives
Fix Media Library
wow-media-library-fix
Fix Media Library inconsistency between database and wp-content/uploads folder contents. Unused image files, broken media library entries, missing att …
Upgrade for Unattach and Re-attach Media Attachments
upgrade-for-unattach-re-attach-media-attachments
Allows to unattach and reattach images and other attachments from within the media library page.
VA Removing Exif
va-removing-exif
Automatically remove all Exif data from the new JPEG images when uploading.
Acclectic Media Organizer
acclectic-media-organizer
A file manager for your media library. Organize your attachments, photos, and other media items into folders, and easily filter items by folder when y …
Attachment Page Comment Control
attachment-page-comment-control
Gives you the ability to turn comments and pings on or off for individual attachment pages within your media library.
Media Search Enhanced Developer Profile
6 plugins · 4K total installs
How We Detect Media Search Enhanced
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-search-enhanced/public/css/media-search-enhanced.css/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js/wp-content/plugins/media-search-enhanced/public/css/media-search-enhanced.css?ver=/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js?ver=HTML / DOM Fingerprints
mse-search-form[mse-search-form]