
Search Meter Security & Risk Analysis
wordpress.org/plugins/search-meterSearch Meter tracks what your readers are searching for on your site. View full details of recent searches or stats for the last day, week or month.
Is Search Meter Safe to Use in 2026?
Generally Safe
Score 98/100Search Meter has a strong security track record. Known vulnerabilities have been patched promptly.
The "search-meter" plugin v2.14.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. Furthermore, there are no identified dangerous functions being used, and the plugin does implement nonce and capability checks, indicating some adherence to secure coding practices. However, significant concerns arise from the SQL query and output escaping practices. A substantial portion of SQL queries are not using prepared statements, which is a common vector for SQL injection vulnerabilities. Similarly, a very low percentage of output is properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while limited, did identify flows with unsanitized paths, which, if exploited, could lead to issues. The vulnerability history is also a significant red flag, with a past critical vulnerability related to code injection. Although this vulnerability is patched, its nature and the presence of unescaped output and non-prepared SQL statements suggest a potential for similar issues to arise.
Key Concerns
- Low percentage of properly escaped output
- High percentage of SQL queries without prepared statements
- Flows with unsanitized paths found in taint analysis
- History of critical code injection vulnerability
Search Meter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Search Meter <= 2.13.2 - Remote Code Execution
Search Meter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Search Meter Attack Surface
WordPress Hooks 8
Maintenance & Trust
Search Meter Maintenance & Trust
Maintenance Signals
Community Trust
Search Meter Alternatives
Search Fixer
search-fixer
Search Fixer makes "pretty" search links work properly. A pretty search link usually looks like this:
Statify Widget
statify-widget
Data privacy conform widget for list popular content (pages, posts, custom post types) – based on Statify plugin.
Search Analytics for WP
search-analytics
Search Analytics for WP will store and display the search terms used on your website. No third-party service is used!
Search Console
search-console
View all your Search Console data inside WordPress dashboard.
Sitekit
sitekit
Widgets: search, archives and categories. Shortcodes: archives, bloginfo, iframe and categories.
Search Meter Developer Profile
6 plugins · 22K total installs
How We Detect Search Meter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-meter/css/search-meter-admin.css/wp-content/plugins/search-meter/css/search-meter-frontend.css/wp-content/plugins/search-meter/js/search-meter-admin.js/wp-content/plugins/search-meter/js/search-meter-frontend.jssearch-meter/css/search-meter-admin.css?ver=search-meter/css/search-meter-frontend.css?ver=search-meter/js/search-meter-admin.js?ver=search-meter/js/search-meter-frontend.js?ver=HTML / DOM Fingerprints
widget_search_metersearch-meter-widgetdata-sm-idsm_admin[search_meter_popular_searches][search_meter_recent_searches]