
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Security & Risk Analysis
wordpress.org/plugins/search-replace-wpcodeSearch and Replace everything in WordPress. Easily find and replace media, images, text, links and more with a single click using a simple user interf …
Is Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Safe to Use in 2026?
Generally Safe
Score 100/100Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "search-replace-wpcode" plugin v1.0.9 exhibits a generally good security posture with several positive indicators. The plugin demonstrates a high percentage of properly escaped output and a significant portion of SQL queries using prepared statements, suggesting a conscious effort towards secure coding practices. The absence of known CVEs and past vulnerabilities further reinforces this positive impression, indicating a mature and likely well-maintained codebase. However, there are specific areas of concern that warrant attention. The presence of one unprotected AJAX handler represents a potential entry point for attackers, especially if it handles user-supplied data without proper validation or authentication. The use of the `unserialize` function, while not inherently a vulnerability, is a known risk factor as it can be exploited if the serialized data originates from an untrusted source. The lack of taint analysis critical or high severity findings is encouraging, but the single unprotected AJAX handler and the `unserialize` function present a non-negligible risk.
Key Concerns
- Unprotected AJAX handler found
- Use of dangerous function (unserialize)
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Security Vulnerabilities
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Release Timeline
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 31
Maintenance & Trust
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Maintenance & Trust
Maintenance Signals
Community Trust
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Alternatives
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Better Find and Replace – AI-Powered Suggestions
real-time-auto-find-and-replace
Search and replace text, images, URLs, footer credits, code blocks or jQuery-Ajax content in real time or in Database, easy user-interface
CM Search And Replace – Optimize content edits with a powerful search and replace tool
cm-on-demand-search-and-replace
Search and replace words, phrases, and HTML within your website posts and pages.
Slider Revolution Search Replace
slider-revolution-search-replace
Replace url of old domain to new domain for revolution slider only.
Sigma Search & Replace
sigma-search-replace
The ultimate search & replace plugin for WordPress. Safely update text, URLs, and serialized data across your entire database with confidence.
Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More Developer Profile
1 plugin · 20K total installs
How We Detect Search & Replace Everything by WPCode – Find and Replace Media, Text, Links, and More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-replace-wpcode/build/admin.css/wp-content/plugins/search-replace-wpcode/build/admin.js/wp-content/plugins/search-replace-wpcode/build/admin.jssearch-replace-wpcode/build/admin.css?ver=search-replace-wpcode/build/admin.js?ver=HTML / DOM Fingerprints
wsrwjs