Premmerce Product Search for WooCommerce Security & Risk Analysis

wordpress.org/plugins/premmerce-search

Premmerce Search makes the WooCommerce product search more flexible and efficient and gives the additional search results due to the spell correction.

1K active installs v2.2.5 PHP 5.6+ WP 4.8+ Updated Feb 19, 2026
ajax-product-searchlive-product-searchproduct-searchwoocommerce-product-search
73
B · Generally Safe
CVEs total3
Unpatched1
Last CVEJul 28, 2025
Safety Verdict

Is Premmerce Product Search for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 73/100

Premmerce Product Search for WooCommerce is generally safe to use. 3 past CVEs were resolved.

3 known CVEs 1 unpatched Last CVE: Jul 28, 2025Updated 2mo ago
Risk Assessment

The "premmerce-search" plugin v2.2.5 presents a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, or cron events lacking proper authentication or permission checks. The code generally shows good practices with a high percentage of SQL queries using prepared statements and a non-zero number of nonce checks. However, a significant concern arises from the vulnerability history. The plugin has a history of three known CVEs, with one still unpatched and rated as High severity. The common vulnerability types (RFI, CSRF, XSS) suggest recurring issues with input validation and authorization, which is worrying. The high percentage of improperly escaped outputs (52%) is a direct indicator of potential cross-site scripting vulnerabilities, further exacerbated by the historical XSS issues. The bundled Freemius library at v1.0 could also be a vector if it contains known vulnerabilities.

While the current version's static analysis indicates a lack of exploitable entry points or obvious code flaws like unsanitized taint flows, the historical pattern of vulnerabilities, particularly the unpatched High severity one, cannot be ignored. This suggests that previous issues may not have been fully remediated or new ones could emerge. The plugin's reliance on historical fixes and the presence of an unpatched high-severity vulnerability indicate a need for immediate attention. The high rate of unescaped output is a critical weakness that directly contributes to the risk of XSS attacks. The overall security is hampered by the unaddressed past vulnerabilities and the ongoing risk of XSS due to insufficient output escaping.

Key Concerns

  • Unpatched High Severity CVE
  • 52% Improperly Escaped Output
  • Bundled Outdated Library (Freemius v1.0)
  • Zero Capability Checks
Vulnerabilities
3 published

Premmerce Product Search for WooCommerce Security Vulnerabilities

CVEs by Year

3 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-60194high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Premmerce Product Search for WooCommerce <= 2.2.4 - Unauthenticated Local File Inclusion

Jul 28, 2025 Patched in 2.2.5 (213d)
CVE-2025-64290medium · 4.3Cross-Site Request Forgery (CSRF)

Premmerce Product Search for WooCommerce <= 2.2.4 - Cross-Site Request Forgery

May 10, 2025 Patched in 2.2.5 (293d)
CVE-2025-64289medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Premmerce Product Search for WooCommerce <= 2.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

May 10, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Premmerce Product Search for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
17 prepared
Unescaped Output
22
20 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

85% prepared20 total queries

Output Escaping

48% escaped42 total outputs
Attack Surface

Premmerce Product Search for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[premmerce_search] src\SearchPlugin.php:144
WordPress Hooks 23
actionafter_uninstallpremmerce-search.php:42
actionadmin_initsrc\Admin\Admin.php:49
actionadmin_menusrc\Admin\Admin.php:50
actionadmin_enqueue_scriptssrc\Admin\Admin.php:51
filteradmin_footer_textsrc\Admin\Admin.php:52
actionrest_api_initsrc\Frontend\RestController.php:56
actionwp_enqueue_scriptssrc\Frontend\RestController.php:63
actionwp_footersrc\Frontend\SearchHandler.php:78
actioninitsrc\Frontend\SearchHandler.php:79
actionparse_querysrc\Frontend\SearchHandler.php:80
filterposts_searchsrc\Frontend\SearchHandler.php:85
filterposts_searchsrc\Frontend\SearchHandler.php:91
filterposts_searchsrc\Frontend\SearchHandler.php:97
filterposts_fieldssrc\Frontend\SearchHandler.php:103
filterposts_search_orderbysrc\Frontend\SearchHandler.php:109
filterwc_get_templatesrc\Frontend\SearchHandler.php:116
filterpremmerce_search_localize_arraysrc\Integration\OceanWpIntegration.php:8
actioninitsrc\SearchPlugin.php:71
actioninitsrc\SearchPlugin.php:72
actionadmin_initsrc\SearchPlugin.php:73
actionbefore_woocommerce_initsrc\SearchPlugin.php:74
filterfreemius_pricing_js_pathsrc\SearchPlugin.php:76
filterhide_account_tabsviews\admin\tabs\account.php:8
Maintenance & Trust

Premmerce Product Search for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.6
Downloads55K

Community Trust

Rating78/100
Number of ratings7
Active installs1K
Developer Profile

Premmerce Product Search for WooCommerce Developer Profile

Premmerce

14 plugins · 60K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
401 days
View full developer profile
Detection Fingerprints

How We Detect Premmerce Product Search for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/premmerce-search/build/css/style.css/wp-content/plugins/premmerce-search/build/js/script.js/wp-content/plugins/premmerce-search/build/js/admin.js
Script Paths
/wp-content/plugins/premmerce-search/build/js/script.js/wp-content/plugins/premmerce-search/build/js/admin.js
Version Parameters
premmerce-search/build/css/style.css?ver=premmerce-search/build/js/script.js?ver=premmerce-search/build/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
premmerce-search-formpremmerce-search-resultspremmerce-search-settings-pagepremmerce-search-affiliate-pagepremmerce-search-account-page
HTML Comments
<!-- premmerce_clear --><!-- /premmerce_clear -->
Data Attributes
data-action-searchdata-plugin-id
JS Globals
PremmerceSearchConfig
REST Endpoints
/wp-json/premmerce-search/v1/search
Shortcode Output
[premmerce_search_form]
FAQ

Frequently Asked Questions about Premmerce Product Search for WooCommerce