
Real-Time Find and Replace Security & Risk Analysis
wordpress.org/plugins/real-time-find-and-replaceSet up find and replace rules that are executed AFTER a page is generated by WordPress, but BEFORE it is sent to a user's browser.
Is Real-Time Find and Replace Safe to Use in 2026?
Generally Safe
Score 98/100Real-Time Find and Replace has a strong security track record. Known vulnerabilities have been patched promptly.
The "real-time-find-and-replace" v4.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a seemingly small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The code also demonstrates good practices regarding SQL queries, using prepared statements exclusively, and includes a nonce check. However, a significant concern arises from the low percentage of properly escaped output (19%), suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history.
The vulnerability history is a major red flag, with two past high-severity vulnerabilities, specifically CSRF and XSS. The fact that there are no currently unpatched vulnerabilities is positive, but the pattern of past XSS and CSRF issues, particularly the last one being in 2020, indicates a historical weakness in input sanitization and output escaping that needs ongoing vigilance. The lack of critical taint flows and dangerous functions in the current analysis is reassuring, but it does not entirely mitigate the risks posed by the poor output escaping.
In conclusion, while the plugin has improved in some areas like SQL handling and reducing its direct attack surface, the significant unescaped output and the historical pattern of XSS and CSRF vulnerabilities point to a moderate to high risk. Users should be cautious, and developers should prioritize addressing the output escaping issues to prevent potential XSS attacks.
Key Concerns
- High percentage of unescaped output
- History of High Severity CVEs (XSS, CSRF)
- Past vulnerabilities indicate ongoing risk
Real-Time Find and Replace Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Real-Time Find and Replace <= 3.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Real-Time Find and Replace <= 3.8 - Cross-Site Scripting
Real-Time Find and Replace Code Analysis
Output Escaping
Data Flow Analysis
Real-Time Find and Replace Attack Surface
WordPress Hooks 3
Maintenance & Trust
Real-Time Find and Replace Maintenance & Trust
Maintenance Signals
Community Trust
Real-Time Find and Replace Alternatives
Easy Search Replace – Find & Replace Text/HTML/URLs, Remove Footer Credit
easy-search-replace
Real-time search & replace for text, HTML, and URLs. Target elements, post types/IDs/URLs. Safely remove footer credit no database changes.
Word Replace
word-replace
Easily Replace text, footer credits, jQuery/Ajax loaded text or anything in real-time.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Go Live Update Urls
go-live-update-urls
Change the domain on your site with one click.
Better Find and Replace – AI-Powered Suggestions
real-time-auto-find-and-replace
Search and replace text, images, URLs, footer credits, code blocks or jQuery-Ajax content in real time or in Database, easy user-interface
Real-Time Find and Replace Developer Profile
7 plugins · 195K total installs
How We Detect Real-Time Find and Replace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/real-time-find-and-replace/css/main.css/wp-content/plugins/real-time-find-and-replace/js/main.js/wp-content/plugins/real-time-find-and-replace/js/main.jsHTML / DOM Fingerprints
far-itemsfar_itemlistside-labelside-label-longid="far-items"id="far_itemlist"name="farfind[]"name="farreplace[]"name="farregex[]"name="faradmin[]"+4 morefar_admin_scriptsaddFormFieldfar_plugin_settings