
Search Exclude Security & Risk Analysis
wordpress.org/plugins/search-excludeHide any post or page from the search results.
Is Search Exclude Safe to Use in 2026?
Generally Safe
Score 93/100Search Exclude has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'search-exclude' plugin version 2.6.3 presents a mixed security posture. On one hand, the static analysis reveals a very small attack surface, with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. The plugin also demonstrates good practices in output escaping, with 96% of outputs properly handled. Furthermore, there are no detected taint flows or dangerous functions within the analyzed code.
However, significant concerns arise from the plugin's vulnerability history. It has a history of 4 known CVEs, with a high severity vulnerability and three medium severity vulnerabilities in the past. The common types of these past vulnerabilities include Missing Authorization and Cross-site Scripting, indicating a pattern of introducing security flaws in these areas. The fact that the last vulnerability was recorded in late 2025 suggests potential for ongoing or recurring issues.
While the current code analysis shows no immediate, exploitable vulnerabilities like unsanitized taint flows or raw SQL queries, the historical pattern of past vulnerabilities, particularly the high and medium severity ones related to authorization and XSS, warrants caution. The presence of SQL queries without prepared statements, though not explicitly linked to a vulnerability in this version's analysis, is a practice that historically leads to SQL injection risks. The plugin's strength lies in its minimal attack surface and good output escaping in this version, but its past security record necessitates vigilance.
Key Concerns
- SQL queries not using prepared statements
- History of high severity vulnerabilities
- History of medium severity vulnerabilities
Search Exclude Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Search Exclude <= 2.5.7 – Missing Authorization to Authenticated (Contributor+) Search Settings Modification via REST API
Search Exclude <= 2.4.9 - Missing Authorization to Unauthenticated Plugin Settings Modification
Search Exclude <= 1.2.6 - Authenticated (Editor+) Stored Cross-Site Scripting
Search Exclude <= 1.2.3 - Arbitrary Settings Change
Search Exclude Release Timeline
Search Exclude Code Analysis
SQL Query Safety
Output Escaping
Search Exclude Attack Surface
WordPress Hooks 24
Maintenance & Trust
Search Exclude Maintenance & Trust
Maintenance Signals
Community Trust
Search Exclude Alternatives
Exclude Search
exclude-search
Exclude posts, pages, products or custom posts from WordPress search results.
Hide from Search
mpress-hide-from-search
Hide individual WordPress pages from search engines and/or WordPress searches, such as confirmation and download pages.
Custom Search by BestWebSoft – WordPress Custom Search Plugin
custom-search-plugin
Add advanced custom search to your WordPress site. Search custom post types, taxonomies, and custom fields with full control over results.
Site Search 360
site-search-360
Precise and fast search, autocompletion, and search suggestions for your WordPress page.
Sort SearchResult By Title
sort-searchresult-by-title
Wordpress sort search results by title offers powerful option for developers to sort search results alphabetically in ascending or descending order.
Search Exclude Developer Profile
17 plugins · 634K total installs
How We Detect Search Exclude
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-exclude/assets/css/backend.css/wp-content/plugins/search-exclude/assets/js/backend.js/wp-content/plugins/search-exclude/assets/js/backend.jssearch-exclude/assets/css/backend.css?ver=search-exclude/assets/js/backend.js?ver=HTML / DOM Fingerprints
qlse-notice-plugin-promoteqlse-feedback-modalqlse-modal-closeqlse-feedback-form-wrapperqlse-feedback-formqlse-feedback-inputqlse-feedback-textareaqlse-feedback-submit+2 more<!-- WP Dashboard Widget News --><!-- WP Plugin Table Links --><!-- WP Plugin Install Tab --><!-- WP Notice Plugin Promote -->+1 moredata-qlse-feedbackdata-qlse-promo-iddata-qlse-plugin-slugwindow.qlse_feedbackwindow.qlse_promo