Microstock Powersearch Plugin Security & Risk Analysis

wordpress.org/plugins/microstock-photo-powersearch-plugin

The Microstock Powersearch Plugin makes it quick and easy to find awesome and affordable stock photographs from microstock photography agencies.

10 active installs v1.0.0 PHP + WP 1.5+ Updated Sep 28, 2010
microstockphotossearchstock-imagesstock-photos
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Microstock Powersearch Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Microstock Powersearch Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'microstock-photo-powersearch-plugin' v1.0.0 exhibits a strong security posture in several key areas. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly without authentication checks, significantly limits the potential attack surface. The code also demonstrates good practices with 100% of SQL queries utilizing prepared statements and a nonce check present. The plugin's vulnerability history is also a positive indicator, with no known CVEs, suggesting a history of secure development or infrequent public exposure of vulnerabilities.

However, a significant concern arises from the low percentage of properly escaped output (5%). This indicates a substantial risk of cross-site scripting (XSS) vulnerabilities. With 22 total outputs analyzed and only a small fraction properly escaped, an attacker could potentially inject malicious scripts that could be executed in a user's browser, leading to session hijacking, credential theft, or other harmful actions. While taint analysis showed no issues, this is likely due to the limited flows analyzed (0). The absence of capability checks on the identified nonce check also warrants attention, as it could be bypassed if not properly integrated with user roles and permissions.

In conclusion, the plugin has a commendable foundation with a minimal attack surface and good SQL handling. The primary weakness lies in output sanitization, presenting a clear XSS risk. The lack of significant historical vulnerabilities is reassuring but does not negate the immediate risks identified in the static analysis. Addressing the output escaping issue is paramount to improving its overall security.

Key Concerns

  • Low percentage of properly escaped output
  • Missing capability checks for nonce
Vulnerabilities
None known

Microstock Powersearch Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Microstock Powersearch Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Microstock Powersearch Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped22 total outputs
Attack Surface

Microstock Powersearch Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initmicro-power-search.php:38
actionadmin_menumicro-power-search.php:40
actionadmin_menumicro-power-search.php:42
actionadmin_headmicro-power-search.php:44
actionadmin_footermicro-power-search.php:45
actiondbx_post_advancedmicro-power-search.php:271
actiondbx_page_advancedmicro-power-search.php:272
Maintenance & Trust

Microstock Powersearch Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedSep 28, 2010
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Microstock Powersearch Plugin Developer Profile

bobbigmac

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Microstock Powersearch Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/microstock-photo-powersearch-plugin/css//wp-content/plugins/microstock-photo-powersearch-plugin/js/
Script Paths
/wp-content/plugins/microstock-photo-powersearch-plugin/js/mps_power_search.js
Version Parameters
microstock-photo-powersearch-plugin/style.css?ver=microstock-photo-powersearch-plugin/js/mps_power_search.js?ver=

HTML / DOM Fingerprints

CSS Classes
mpslangmps_power_search_configuration
Data Attributes
id="mpslang"name="mpslang"id="mpslang_view"name="mpslang_view"name="mps_metadata"
JS Globals
mps_updateTextInfo
FAQ

Frequently Asked Questions about Microstock Powersearch Plugin