
SD Live Search Security & Risk Analysis
wordpress.org/plugins/sd-live-searchSD live seacrh is a basic search plugin for search lively.
Is SD Live Search Safe to Use in 2026?
Generally Safe
Score 85/100SD Live Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sd-live-search" plugin v1.0.1 exhibits a mixed security posture. On the positive side, there are no recorded CVEs and the plugin avoids dangerous functions, file operations, and external HTTP requests. All SQL queries are correctly prepared, which is a strong defense against SQL injection. The limited attack surface consisting of only two shortcodes and no AJAX handlers or REST API routes is also a positive indicator, especially since none of these entry points appear to be unprotected.
However, there are significant concerns that temper this positive outlook. The most critical issue is the extremely low output escaping rate (25%), indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks, coupled with the lack of any taint analysis data, suggests that the plugin may not be adequately validating user input or enforcing permissions, potentially opening it up to other attacks if the shortcodes handle user-supplied data.
Given the clean vulnerability history, it's possible the plugin hasn't been extensively tested or targeted. However, the identified weaknesses in output escaping and the absence of security checks are fundamental security oversights that should be addressed. The current assessment suggests a plugin that has avoided known issues but has inherent vulnerabilities due to poor coding practices in key areas.
Key Concerns
- Low output escaping rate (25%)
- 0 Nonce checks
- 0 Capability checks
- 0 Taint flows analyzed
SD Live Search Security Vulnerabilities
SD Live Search Code Analysis
Output Escaping
SD Live Search Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
SD Live Search Maintenance & Trust
Maintenance Signals
Community Trust
SD Live Search Alternatives
Ajax Search Lite – Live Search & Filter
ajax-search-lite
The Best Ajax Live Search and Filter for WordPress. Live suggestions, Custom Post types, Custom fields, Categories, WooCommerce & Elementor support
Advanced Woo Search – Product Search for WooCommerce
advanced-woo-search
Advanced WooCommerce product search plugin. Search inside any product field. Support for both AJAX search and search results page.
Advanced Product Search For WooCommerce
advanced-product-search-for-woo
Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.
Events Search For The Events Calendar
events-search-addon-for-the-events-calendar
Adds an AJAX-based events search bar on any page via shortcode to quickly find any upcoming event created with The Events Calendar plugin.
Predictive Search for WooCommerce
woocommerce-predictive-search
Predictive Search for WooCommerce gives your customers an awesome search experience delivering stunning 'live' product search results.
SD Live Search Developer Profile
3 plugins · 180 total installs
How We Detect SD Live Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sd-live-search/style.css/wp-content/plugins/sd-live-search/js/live-search.js/wp-content/plugins/sd-live-search/js/live-search.jssd-live-search/style.css?ver=sd-live-search/js/live-search.js?ver=HTML / DOM Fingerprints
ult_searchformbsf-mainblog-grid-masonrybsf-listpost-itembsf-subbsf-sub-listbsf-list1<!-- sub category posts --><!-- sub category single --><!-- sub category list --><!-- main category single -->+1 moreid="ult_searchform"id="s"id="ult_searchsubmit"class="bsf-main blog-grid-masonry"class="bsf-list post-item"class="fa fa-folder folder-icon"+5 morejQuery('#ult_searchform input[name=s]').liveSearch({url: '/?s='});<form role="search" method="get" id="ult_searchform" action="Enter a search termSearch<div class="entry-title">