
Relevant Search Security & Risk Analysis
wordpress.org/plugins/relevant-searchRelevant Search replaces the default WordPress search with relevant results.
Is Relevant Search Safe to Use in 2026?
Generally Safe
Score 85/100Relevant Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'relevant-search' plugin v1.2.0 appears to have a strong security posture. The plugin reports zero entry points, meaning there are no AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. Furthermore, the code analysis shows no dangerous functions, file operations, external HTTP requests, or bundled libraries, which are common vectors for vulnerabilities. The absence of any known CVEs and a clean vulnerability history reinforces this positive assessment, suggesting a commitment to secure coding practices.
However, a significant concern arises from the SQL query handling. All four SQL queries are executed without using prepared statements. This presents a substantial risk of SQL injection vulnerabilities, as user-supplied data could be directly interpreted as SQL commands. While the output escaping is 100% effective and taint analysis shows no issues, the raw SQL queries are a critical weakness that could be exploited if an attacker can influence the data used in these queries. The lack of nonce and capability checks, coupled with no apparent AJAX or REST API endpoints to test these against, makes it difficult to fully assess the risk in those areas, but the underlying SQL risk is undeniable.
In conclusion, while the plugin excels in minimizing its attack surface and handling output safely, the unmitigated risk of SQL injection due to the complete lack of prepared statements is a major security flaw. The zero CVE history is a positive sign, but it does not negate the direct evidence of a significant vulnerability within the codebase. This plugin is generally well-coded in many aspects, but the SQL vulnerability needs immediate attention.
Key Concerns
- Raw SQL queries without prepared statements
Relevant Search Security Vulnerabilities
Relevant Search Code Analysis
SQL Query Safety
Output Escaping
Relevant Search Attack Surface
WordPress Hooks 3
Maintenance & Trust
Relevant Search Maintenance & Trust
Maintenance Signals
Community Trust
Relevant Search Alternatives
Better Search – Relevant search results for WordPress
better-search
Better Search replaces the default WordPress search with a better search engine that gives contextual results sorted by relevance.
WP Fast Total Search – The Power of Indexed Search
fulltext-search
Extends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
Swiftype Site Search Plugin for WordPress
swiftype-search
Fast, intelligent, and fully customizable search for your site.
Yext AI Search
yext-ai-search
Add the world's best search experience to your website in minutes.
Yext Answers Site Search
yext-answers
This plugin is no longer being maintained. If you are looking to add Answers to your Wordpress site, please use our new plugin: https://wordpress.
Relevant Search Developer Profile
2 plugins · 50 total installs
How We Detect Relevant Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
relevat_search