
Search by Google Security & Risk Analysis
wordpress.org/plugins/search-googleSearch by Google widget.
Is Search by Google Safe to Use in 2026?
Use With Caution
Score 63/100Search by Google has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "search-google" plugin v1.9 exhibits a mixed security posture. While it has no identified entry points in the static analysis (AJAX, REST API, shortcodes, cron), indicating a small attack surface, several code signals raise concerns. The presence of the dangerous `create_function` is a significant red flag, as it can lead to code injection vulnerabilities if user input is not meticulously sanitized before being passed to it. Furthermore, only 29% of output is properly escaped, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities where untrusted data could be rendered in the browser without adequate sanitization.
The plugin's vulnerability history shows one known medium severity CVE related to XSS, which is currently unpatched. This unpatched vulnerability, combined with the static analysis findings pointing to potential XSS issues (low output escaping), strongly suggests that the plugin is susceptible to XSS attacks. The lack of nonce checks and capability checks, while not directly penalized due to the absence of unprotected entry points, are generally considered good security practices that are missing here. Overall, the absence of immediate critical threats in taint analysis is positive, but the presence of the dangerous function and poor output escaping, alongside an unpatched XSS vulnerability, creates a substantial risk.
In conclusion, while the plugin's limited attack surface is a strength, the code quality issues, particularly the use of `create_function` and inadequate output escaping, coupled with an unpatched XSS vulnerability, significantly lower its security. Users should exercise caution and prioritize updating or replacing this plugin. The identified risks are not theoretical but are supported by both static analysis and historical vulnerability data.
Key Concerns
- Unpatched CVE (medium severity)
- Dangerous function: create_function
- Low output escaping (29%)
- Missing nonce checks
- Missing capability checks
Search by Google Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Search by Google <= 1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Search by Google Code Analysis
Dangerous Functions Found
Output Escaping
Search by Google Attack Surface
WordPress Hooks 4
Maintenance & Trust
Search by Google Maintenance & Trust
Maintenance Signals
Community Trust
Search by Google Alternatives
Search Console
search-console
View all your Search Console data inside WordPress dashboard.
Ad Widget for WordPress
ad-widget
Easily upload ad images and ad code to your sidebar. For those that don't need or want a complicated ad management system.
Search Engine Insights for Google Search Console
search-engine-insights
Verify site ownership on Google Search Console! Analyze the Google Search Console stats, to see your site's performance on Google Search.
Amikelive Adsense Widget
amikelive-adsense-widget
This plugin enables Google adsense display on the sidebar or widget area only by activating and configuring the widget.
Live Search Popup
live-search-popup
Spotlight (tm) like live search with an ajax popup
Search by Google Developer Profile
14 plugins · 128K total installs
How We Detect Search by Google
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-google/css/search-google.css/wp-content/plugins/search-google/js/search-google.js/wp-content/plugins/search-google/js/search-google.jssearch-google/css/search-google.css?ver=search-google/js/search-google.js?ver=HTML / DOM Fingerprints
widget_search_googlesearch_google_formpseudoqpseudositesearchgoogle<!-- Search by Google plugin v.pseudoqpseudositesearchgooglebtnG