Media Search Enhanced Security & Risk Analysis

wordpress.org/plugins/media-search-enhanced

Search through all fields in Media Library.

3K active installs v0.9.2 PHP + WP 3.5+ Updated Jan 21, 2026
attachmentmediamedia-library
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 7, 2026
Safety Verdict

Is Media Search Enhanced Safe to Use in 2026?

Generally Safe

Score 99/100

Media Search Enhanced has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 7, 2026Updated 2mo ago
Risk Assessment

The "media-search-enhanced" plugin v0.9.2 demonstrates some good security practices, notably the exclusive use of prepared statements for all SQL queries and proper output escaping. The static analysis also shows no critical or high severity taint flows, a clean slate for file operations and external HTTP requests. The attack surface is minimal with only one shortcode and no unprotected entry points identified in this analysis.

However, there are significant concerns. The plugin completely lacks nonce checks and capability checks. This means that any authenticated user, regardless of their role, could potentially trigger actions associated with the shortcode. The presence of a past medium severity SQL injection vulnerability, even if currently patched, is a red flag and suggests potential for similar issues if sanitization or input validation is not consistently applied. The fact that a vulnerability was recorded as recently as 2026-01-07 (though likely a typo and meant to be in the past) also warrants attention.

In conclusion, while the plugin has made strides in secure coding for SQL and output handling, the absence of proper authorization and capability checks presents a substantial risk. Coupled with the history of an SQL injection vulnerability, this plugin requires careful monitoring and potentially further security hardening before being considered robustly secure.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Past medium SQL injection vulnerability
Vulnerabilities
1

Media Search Enhanced Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-23805medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Media Search Enhanced <= 0.9.1 - Authenticated (Author+) SQL Injection

Jan 7, 2026 Patched in 0.9.2 (51d)
Code Analysis
Analyzed Mar 16, 2026

Media Search Enhanced Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

Media Search Enhanced Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mse-search-form] public\class-media-search-enhanced.php:72
WordPress Hooks 6
actionplugins_loadedmedia-search-enhanced.php:46
actioninitpublic\class-media-search-enhanced.php:66
filterposts_clausespublic\class-media-search-enhanced.php:69
filterthe_excerptpublic\class-media-search-enhanced.php:75
filterattachment_linkpublic\class-media-search-enhanced.php:78
filterget_search_formpublic\class-media-search-enhanced.php:81
Maintenance & Trust

Media Search Enhanced Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 21, 2026
PHP min version
Downloads44K

Community Trust

Rating88/100
Number of ratings27
Active installs3K
Developer Profile

Media Search Enhanced Developer Profile

Yoren Chang

6 plugins · 4K total installs

79
trust score
Avg Security Score
87/100
Avg Patch Time
51 days
View full developer profile
Detection Fingerprints

How We Detect Media Search Enhanced

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-search-enhanced/public/css/media-search-enhanced.css/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js
Script Paths
/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js
Version Parameters
/wp-content/plugins/media-search-enhanced/public/css/media-search-enhanced.css?ver=/wp-content/plugins/media-search-enhanced/public/js/media-search-enhanced.js?ver=

HTML / DOM Fingerprints

Data Attributes
mse-search-form
Shortcode Output
[mse-search-form]
FAQ

Frequently Asked Questions about Media Search Enhanced