
Relevanssi Light Security & Risk Analysis
wordpress.org/plugins/relevanssi-lightRelevanssi Light is a simple, quick and effective search improvement that replaces the default WP search with a fulltext index search.
Is Relevanssi Light Safe to Use in 2026?
Generally Safe
Score 100/100Relevanssi Light has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The relevanssi-light v1.2.2 plugin exhibits a generally good security posture, with a clean vulnerability history and a limited attack surface. The absence of known CVEs and a lack of critical or high-severity taint flows are positive indicators. The plugin utilizes prepared statements for a majority of its SQL queries, which is a good practice. However, there are notable areas for improvement. The most significant concern is the complete lack of output escaping for all identified output points. This could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is reflected directly in the output without proper sanitization. Additionally, while there are no unauthenticated AJAX handlers in this version, the presence of capability checks is zero, which, in combination with the AJAX handlers, suggests a potential oversight in ensuring that sensitive operations are only performed by authorized users. The limited number of total flows analyzed in taint analysis also means the coverage might not be exhaustive.
Key Concerns
- No output escaping for identified outputs
- Zero capability checks on entry points
Relevanssi Light Security Vulnerabilities
Relevanssi Light Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Relevanssi Light Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
Relevanssi Light Maintenance & Trust
Maintenance Signals
Community Trust
Relevanssi Light Alternatives
WP Fast Total Search – The Power of Indexed Search
fulltext-search
Extends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
Full-Text Search
full-text-search
Replaces site search with full-text search.
WPFTS Add-on for WP-Filebase Pro
wpfts-add-on-for-wp-filebase-pro
This plugin adds a data bridge between WP-Filebase Pro plugin and WP Fulltext Search Pro (WPFTS) plugin to allow WPFTS index and search files, uploade …
WPFTS Add-on for WP Download Manager
wpfts-add-on-for-wp-download-manager
This plugin adds a data bridge between WP Download Manager plugin and WP Fulltext Search Pro (WPFTS) plugin to allow WPFTS index and search files, upl …
Wow FullText Search
wow-fulltext-search
Fast fulltext search provided by Search Engine software replacing default WordPress functionality.
Relevanssi Light Developer Profile
4 plugins · 107K total installs
How We Detect Relevanssi Light
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/relevanssi-light/relevanssi-light-admin-ajax.php/wp-content/plugins/relevanssi-light/relevanssi-light-menu.phpHTML / DOM Fingerprints
Copyright 2022 Mikko Saari (email: mikko@mikkosaari.fi)This file is part of Relevanssi Light, a search plugin for WordPress.Relevanssi Light is free software: you can redistribute and/or modifyit under the terms of the GNU General Public License as published by+8 more