
Media Used Search Security & Risk Analysis
wordpress.org/plugins/media-used-searchIf you are using a custom field associated with the post to image, to view the post that you are using the media list.
Is Media Used Search Safe to Use in 2026?
Generally Safe
Score 85/100Media Used Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "media-used-search" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The absence of file operations and external HTTP requests is also a good sign. Furthermore, the vulnerability history is clean, with no known CVEs, suggesting a relatively stable past.
However, the code analysis reveals significant concerns. A critical weakness is the complete lack of capability checks, meaning any user, regardless of their role, could potentially interact with functionalities that might have underlying security implications, even if not immediately apparent from the limited entry points. The static analysis also flags that 100% of the identified SQL queries are not using prepared statements, which is a serious vulnerability that could lead to SQL injection attacks. Only 10% of output escaping is properly done, leaving a high risk of Cross-Site Scripting (XSS) vulnerabilities when data is displayed to users.
While the plugin has no known historical vulnerabilities and a minimal attack surface, the identified code-level weaknesses in handling SQL and output escaping present a substantial risk. The absence of capability checks is a fundamental security oversight. Therefore, despite the lack of historical exploits and a small attack surface, the current implementation has critical flaws that need immediate attention. The plugin is not recommended for production use in its current state without significant code remediation.
Key Concerns
- No capability checks implemented
- 100% of SQL queries not using prepared statements
- Only 10% of output escaping properly done
Media Used Search Security Vulnerabilities
Media Used Search Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Used Search Attack Surface
WordPress Hooks 8
Maintenance & Trust
Media Used Search Maintenance & Trust
Maintenance Signals
Community Trust
Media Used Search Alternatives
WP Quick Update Featured Image
wp-quick-update-featured-image
Adds ability to make available payment method according IP address.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
WEN Featured Image
wen-featured-image
Add featured image column in listings. Add/change/remove featured image directly from the listing page
Custom Header Extended
custom-header-extended
Allows users to create a custom header on a per-post basis.
Find Posts Using Attachment
find-posts-using-attachment
Allows to find all posts where a particular attachment is used.
Media Used Search Developer Profile
1 plugin · 10 total installs
How We Detect Media Used Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-used-search/css/mus-admin.css/wp-content/plugins/media-used-search/js/mus-admin.jsHTML / DOM Fingerprints
mus_admin_wrapdata-mus-used-postsMediaUsedSearch