
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Security & Risk Analysis
wordpress.org/plugins/searchjet-instant-searchAI-powered instant search for WordPress & WooCommerce with typo tolerance and real-time analytics.
Is SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Safe to Use in 2026?
Generally Safe
Score 100/100SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "searchjet-instant-search" plugin v1.3.6 exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions, using prepared statements for all SQL queries, and a history free of known vulnerabilities, several areas raise concerns. The significant number of REST API routes (10 out of 13) lacking permission callbacks is a substantial risk, as it exposes sensitive functionality to unauthorized users. Similarly, a high proportion of AJAX handlers (4 total, with 0 explicitly noted as unprotected, but this could be implied by the REST API findings) and a flow with an unsanitized path in the taint analysis point to potential injection or path traversal vulnerabilities if not handled carefully within the context of those unprotected endpoints.
The absence of any recorded CVEs and a clean vulnerability history suggest a generally well-maintained codebase or a lack of significant past security issues. However, the current static analysis results highlight critical areas that require immediate attention. The large attack surface presented by unprotected REST API routes and the single unsanitized path flow are the most pressing concerns. The plugin's strengths lie in its use of prepared statements and lack of dangerous functions, but these are overshadowed by the potential for unauthorized access and code execution due to insufficient access controls on its entry points. A balanced approach would involve addressing these identified weaknesses while acknowledging the existing good security practices.
Key Concerns
- REST API routes without permission callbacks
- Flow with unsanitized paths
- Unprotected AJAX handlers
- Output escaping below 100%
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Security Vulnerabilities
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Release Timeline
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Code Analysis
Output Escaping
Data Flow Analysis
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Attack Surface
AJAX Handlers 4
REST API Routes 13
Shortcodes 2
WordPress Hooks 70
Scheduled Events 3
Maintenance & Trust
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Maintenance & Trust
Maintenance Signals
Community Trust
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Alternatives
Dynamic Data Search
dynamic-data-search
Fast and lightweight AJAX-powered search for WordPress with WooCommerce and Gutenberg template support.
Swift Woo Search – eCommerce Live Search
swift-woo-search-ecommerce-live-search
A lightweight, fast and customizable AJAX search plugin for WooCommerce stores. Boost your shop's UX and conversion rate with instant product results.
Ivory Search – WordPress Search Plugin
add-search-to-menu
Advanced WordPress custom search plugin. Provides Search Form Customizer, WooCommerce Search, AJAX Search & Live Search support!
FiboSearch – Ajax Search for WooCommerce
ajax-search-for-woocommerce
The most popular WooCommerce product search plugin. Gives your users a well-designed advanced AJAX search bar with live search suggestions.
Advance Product Search- Voice & Ajax Search for WooCommerce
th-advance-product-search
Advanced Product Search boosts your store search with instant AJAX results, live suggestions, and smart category filtering, helping customers find pro …
SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress Developer Profile
12 plugins · 1K total installs
How We Detect SearchJetEngine – AI-Powered Instant Search for WooCommerce & WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/searchjet-instant-search/build/assets/css/admin.css/wp-content/plugins/searchjet-instant-search/build/assets/css/frontend.css/wp-content/plugins/searchjet-instant-search/build/assets/js/frontend.js/wp-content/plugins/searchjet-instant-search/build/assets/js/frontend.jssearchjet-instant-search/build/assets/css/admin.css?ver=searchjet-instant-search/build/assets/css/frontend.css?ver=searchjet-instant-search/build/assets/js/frontend.js?ver=HTML / DOM Fingerprints
searchjet-search-formsearchjet-search-inputsearchjet-search-buttonsearchjet-results-containersearchjet-result-itemsearchjet-result-thumbnailsearchjet-result-titlesearchjet-result-price+6 moredata-searchjet-api-keydata-searchjet-project-iddata-searchjet-search-iddata-searchjet-placeholderdata-searchjet-min-charsdata-searchjet-max-results+11 moreSearchJet