
Search For Custom Fields Security & Risk Analysis
wordpress.org/plugins/search-for-custom-fieldsCreate your own fields for your posts / pages and propose a search based on these fields to your visitors.
Is Search For Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Search For Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "search-for-custom-fields" plugin version 1.2 exhibits a generally strong security posture with a key strength being the exclusive use of prepared statements for all SQL queries, mitigating SQL injection risks. Furthermore, the absence of known CVEs and no recorded historical vulnerabilities suggest a history of responsible development or a lack of targeted exploitation. However, significant concerns arise from the taint analysis, which identified two flows with unsanitized paths, classified as high severity. These flows, despite not directly leading to critical vulnerabilities in this analysis, indicate potential pathways for attackers to manipulate data or functionality if exploited in conjunction with other weaknesses or if the paths lead to sensitive operations.
Another area of concern is the output escaping, where only 55% of outputs are properly escaped. This leaves a substantial portion of the plugin's output vulnerable to Cross-Site Scripting (XSS) attacks, especially considering the two shortcodes present which often serve as entry points for user-supplied data that can be reflected back to the user. While the attack surface is limited to these two shortcodes and no AJAX or REST API routes were found unprotected, the combination of unsanitized paths and insufficient output escaping presents a notable risk that requires immediate attention.
Key Concerns
- High severity taint flows with unsanitized paths
- Insufficient output escaping (45% unescaped)
Search For Custom Fields Security Vulnerabilities
Search For Custom Fields Release Timeline
Search For Custom Fields Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Search For Custom Fields Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Search For Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Search For Custom Fields Alternatives
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
Custom Search by BestWebSoft – WordPress Custom Search Plugin
custom-search-plugin
Add advanced custom search to your WordPress site. Search custom post types, taxonomies, and custom fields with full control over results.
MB FacetWP Integration
meta-box-facetwp-integrator
Integrates Meta Box custom fields with FacetWP. Make custom fields filterable.
Simple SEO Improvements
simple-seo-improvements
Lightweight SEO solution to power up your website.
WP-Admin Search Post Meta
wp-admin-search-meta
Search WordPress admin posts by custom fields (post meta) directly from the default search.
Search For Custom Fields Developer Profile
1 plugin · 10 total installs
How We Detect Search For Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-for-custom-fields/sfcf_widget.jsHTML / DOM Fingerprints
sfcf_field_input<!-- Widget Search For Custom Fields --><!-- Widget Search For Custom Fields -->data-sfcf-optionssfcf_widget_options[sfcf_shortcode][sfcf_search_shortcode]