SD Smart Text Replacer Security & Risk Analysis

wordpress.org/plugins/sd-smart-text-replacer

A Gutenberg sidebar panel that lets you find and replace text in your post content in real-time.

0 active installs v1.0.0 PHP 7.4+ WP 6.9+ Updated Unknown
block-editoreditorfind-and-replacegutenbergtext-replace
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SD Smart Text Replacer Safe to Use in 2026?

Generally Safe

Score 100/100

SD Smart Text Replacer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "sd-smart-text-replacer" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The code does not utilize any dangerous functions, all SQL queries are properly prepared, and output escaping is handled correctly. There are no file operations or external HTTP requests, and importantly, the analysis shows a complete lack of identified taint flows. This indicates a well-written and secure codebase for the current version.

However, a significant concern arises from the complete absence of capability checks and nonce checks across all identified entry points. While the analysis indicates zero unprotected entry points and zero AJAX handlers, the lack of any explicit authorization mechanisms means that if any entry points *were* to be discovered or introduced in future versions, they could potentially be exploited without proper authentication or authorization. The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign. This, combined with the clean code analysis, suggests a developer who is likely aware of security best practices. Nevertheless, the missing authorization checks represent a foundational security weakness that, while not currently exploitable due to the limited attack surface, leaves room for future vulnerabilities.

In conclusion, the plugin is technically sound and free of common vulnerabilities in its current state. The developer has demonstrated good practices in areas like SQL and output handling. The primary weakness lies in the lack of robust authorization checks, which is a potential future risk. For this specific version and analysis, the risk is low, but it's a critical area for improvement to maintain long-term security.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

SD Smart Text Replacer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SD Smart Text Replacer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

SD Smart Text Replacer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionenqueue_block_editor_assetssd-smart-text-replacer.php:82
Maintenance & Trust

SD Smart Text Replacer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads114

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SD Smart Text Replacer Developer Profile

Sadhan Pal

9 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SD Smart Text Replacer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sd-smart-text-replacer/includes/script.js/wp-content/plugins/sd-smart-text-replacer/includes/style.css
Script Paths
wp-content/plugins/sd-smart-text-replacer/includes/script.js
Version Parameters
sd-smart-text-replacer/includes/style.css?ver=sd-smart-text-replacer/includes/script.js?ver=

HTML / DOM Fingerprints

JS Globals
sdsmtxtrplcr
FAQ

Frequently Asked Questions about SD Smart Text Replacer