OmniMind Integration Security & Risk Analysis

wordpress.org/plugins/omnimind

Seamlessly connect your website with OmniMind to automate your content management and search processes.

0 active installs v1.0.9 PHP 7.3+ WP 5.3+ Updated Sep 10, 2024
aichatgptsearch
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OmniMind Integration Safe to Use in 2026?

Generally Safe

Score 92/100

OmniMind Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The Omnimind plugin version 1.0.9 presents a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, consistently using prepared statements, and effectively escapes nearly all its output. The plugin also incorporates a substantial number of nonce and capability checks, indicating an awareness of security fundamentals. Furthermore, its vulnerability history is clean, with no recorded CVEs, suggesting a generally stable and well-maintained codebase.

However, a significant concern arises from the attack surface. With a total of 7 entry points, 6 of which are AJAX handlers lacking any authentication checks, this creates a substantial risk. This means attackers could potentially trigger these handlers without proper authorization. The presence of unsanitized paths in the taint analysis, while not leading to critical or high severity flows in this instance, still warrants attention as it points to potential avenues for exploitation if combined with other vulnerabilities or if the analysis missed subtle issues.

In conclusion, while Omnimind has built a solid foundation with secure SQL handling and output escaping, the unprotected AJAX handlers represent a critical security weakness that significantly elevates its risk profile. The absence of vulnerabilities in its history is a strength, but it does not negate the immediate dangers posed by the exposed entry points. Addressing the unprotected AJAX handlers should be the highest priority for improving the plugin's security.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

OmniMind Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OmniMind Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
149 escaped
Nonce Checks
13
Capability Checks
2
File Operations
1
External Requests
11
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped150 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

9 flows3 with unsanitized paths
<ClassAdmin> (src\Admin\ClassAdmin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

OmniMind Integration Attack Surface

Entry Points7
Unprotected6

AJAX Handlers 6

noprivwp_ajax_omni_search_handle_queryomnimind.php:71
authwp_ajax_omni_search_handle_queryomnimind.php:72
noprivwp_ajax_omni_handle_autocompleteomnimind.php:75
authwp_ajax_omni_handle_autocompleteomnimind.php:76
authwp_ajax_create_project_actionomnimind.php:79
authwp_ajax_sync_data_actionomnimind.php:84

Shortcodes 1

[omni_search] omnimind.php:87
WordPress Hooks 10
actionadmin_initomnimind.php:81
actionadmin_initomnimind.php:82
actionadd_meta_boxesomnimind.php:83
actionsave_postomnimind.php:85
actionplugins_loadedomnimind.php:91
actionbulk_edit_custom_boxsrc\Admin\ClassAdmin.php:166
actionquick_edit_custom_boxsrc\Admin\ClassAdmin.php:167
actionadmin_enqueue_scriptssrc\Admin\ClassAssets.php:25
actionadmin_menusrc\Admin\ClassNav.php:26
actionwp_enqueue_scriptssrc\Front\ClassAssets.php:25
Maintenance & Trust

OmniMind Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 10, 2024
PHP min version7.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

OmniMind Integration Developer Profile

Procoders

7 plugins · 400 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OmniMind Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/omnimind/assets/css/omnimind.css/wp-content/plugins/omnimind/assets/vendor/datatables/datatables.min.css/wp-content/plugins/omnimind/assets/vendor/select2/select2.min.css/wp-content/plugins/omnimind/assets/js/omnimind.js/wp-content/plugins/omnimind/assets/vendor/datatables/datatables.min.js/wp-content/plugins/omnimind/assets/vendor/select2/select2.min.js/wp-content/plugins/omnimind/assets/css/omni-wp-search.css/wp-content/plugins/omnimind/assets/js/omni-wp-search.js
Script Paths
/wp-content/plugins/omnimind/assets/js/omnimind.js/wp-content/plugins/omnimind/assets/vendor/datatables/datatables.min.js/wp-content/plugins/omnimind/assets/vendor/select2/select2.min.js/wp-content/plugins/omnimind/assets/js/omni-wp-search.js
Version Parameters
../../assets/css/omnimind.css?ver=../../assets/vendor/datatables/datatables.min.css?ver=../../assets/vendor/select2/select2.min.css?ver=../../assets/js/omnimind.js?ver=../../assets/vendor/datatables/datatables.min.js?ver=../../assets/vendor/select2/select2.min.js?ver=../../assets/css/omni-wp-search.css?ver=../../assets/js/omni-wp-search.js?ver=

HTML / DOM Fingerprints

CSS Classes
omni_columnomni-search-containeromni-search-inputomni-search-buttonomni-autocomplete-results
Data Attributes
data-noncedata-search-url
JS Globals
omni_ajax
Shortcode Output
[omni_search]
FAQ

Frequently Asked Questions about OmniMind Integration