
Search Everything Security & Risk Analysis
wordpress.org/plugins/search-everythingSearch Everything increases WordPress' default search functionality in three easy steps.
Is Search Everything Safe to Use in 2026?
Mostly Safe
Score 81/100Search Everything is generally safe to use though it hasn't been updated recently. 4 past CVEs were resolved.
The "search-everything" plugin v8.1.9 exhibits a mixed security posture. While it demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and includes some nonce and capability checks, significant concerns arise from its attack surface and code analysis.
The plugin has a single unprotected AJAX handler, representing a direct entry point for unauthenticated attackers. Furthermore, the static analysis reveals a dangerous function (`create_function`) which is a known vector for code injection vulnerabilities. The taint analysis, though limited in scope, identified flows with unsanitized paths, indicating a potential for sensitive data to be manipulated or exposed if exploited, although no critical or high severity issues were found in this specific analysis.
The plugin's vulnerability history is particularly concerning. With four known CVEs, three of which are critical, and a common pattern of SQL injection and CSRF vulnerabilities, this indicates a recurring problem with securing input and preventing malicious actions. The fact that all previously reported critical vulnerabilities are now patched is a positive sign, but the historical trend highlights a need for more robust security measures.
In conclusion, while the plugin has made improvements in areas like SQL statement preparation, the presence of unprotected entry points, the use of dangerous functions, and a history of critical vulnerabilities necessitate a cautious approach. The risk is elevated due to the potential for attackers to leverage the unprotected AJAX handler and the historical patterns of severe security flaws.
Key Concerns
- Unprotected AJAX handler
- Use of dangerous function: create_function
- Flows with unsanitized paths
- Vulnerability history: 3 critical CVEs
- Vulnerability history: 1 medium CVE
- Low percentage of properly escaped output
Search Everything Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Search Everything <= 8.1.6 - SQL Injection
Search Everything <= 8.1.5 - SQL Injection
Search Everything <= 8.1 - Cross-Site Request Forgery
Search Everything <= 7.0.2 - SQL Injection
Search Everything Release Timeline
Search Everything Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Search Everything Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Maintenance & Trust
Search Everything Maintenance & Trust
Maintenance Signals
Community Trust
Search Everything Alternatives
Combined Search
combined-search
Forked from the popular WordPress Search Everything plugin, Combined Search allows you to search all available content types on your web site.
WP Extended Search
wp-extended-search
Extend search functionality to search in selected post meta, taxonomies, post types, and all authors.
EchBay Search Everything
echbay-search-everything
Search Everything increases WordPress' default search functionality in three easy steps.
Advance Product Search- Voice & Ajax Search for WooCommerce
th-advance-product-search
Advanced Product Search boosts your store search with instant AJAX results, live suggestions, and smart category filtering, helping customers find pro …
GA Admin Taxonomy Search
ga-admin-taxonomy-search
Make it easy to search/filter items in your admin categories meta box.
Search Everything Developer Profile
2 plugins · 10K total installs
How We Detect Search Everything
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-everything/css/style.css/wp-content/plugins/search-everything/css/admin.css/wp-content/plugins/search-everything/css/jquery.autocomplete.css/wp-content/plugins/search-everything/js/se-admin.js/wp-content/plugins/search-everything/js/se-admin-options.js/wp-content/plugins/search-everything/js/se-admin-metabox.js/wp-content/plugins/search-everything/js/se-admin-save.js/wp-content/plugins/search-everything/js/se-admin-autocomplete.js+1 morehttps://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.jshttps://ajax.googleapis.com/ajax/libs/jqueryui/1.9.1/jquery-ui.min.jssearch-everything/css/style.css?ver=search-everything/css/admin.css?ver=search-everything/css/jquery.autocomplete.css?ver=search-everything/js/se-admin.js?ver=search-everything/js/se-admin-options.js?ver=search-everything/js/se-admin-metabox.js?ver=search-everything/js/se-admin-save.js?ver=search-everything/js/se-admin-autocomplete.js?ver=search-everything/js/se-admin-search-fields.js?ver=HTML / DOM Fingerprints
se-admin-field-wrapse-optionsse-metaboxsearch-everything-containerse-search-filter-wrap<!-- Search Everything Admin Options --><!-- Search Everything Admin Metabox --><!-- Search Everything Global Notice -->data-se-optionsdata-se-metaboxdata-se-search-fieldsse_admin_autocomplete_params