Simple Ajax Search Security & Risk Analysis

wordpress.org/plugins/simple-ajax-search

Easily create a dynamic ajax search engine for your blog.

10 active installs v1.0.1 PHP 5.2.4+ WP 4.6+ Updated Unknown
ajaxblogsearchsearch-engineseeker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Ajax Search Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Ajax Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "simple-ajax-search" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it shows good practices by not utilizing dangerous functions, avoiding raw SQL queries, and having a clean vulnerability history with no known CVEs. The presence of a nonce check is also a positive sign for at least one entry point. However, significant concerns arise from the attack surface analysis. Two AJAX handlers are present, and critically, both lack authentication checks, presenting a direct pathway for unauthenticated attackers to interact with the plugin's functionality. While taint analysis shows no issues, the absence of capability checks on these AJAX handlers, combined with the lack of input sanitization evident from the unescaped outputs (21% of them), creates a notable risk of Cross-Site Scripting (XSS) or other injection attacks if the AJAX handlers process user-supplied data without proper validation and sanitization.

Key Concerns

  • AJAX handlers without auth checks
  • Unescaped output (21% of outputs)
  • No capability checks on AJAX handlers
Vulnerabilities
None known

Simple Ajax Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Ajax Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
11 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped14 total outputs
Attack Surface
2 unprotected

Simple Ajax Search Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_simple_ajax_searchcore\class-simple-ajax-search.php:193
noprivwp_ajax_simple_ajax_searchcore\class-simple-ajax-search.php:194

Shortcodes 2

[sas-input] core\class-simple-ajax-search.php:196
[sas-result] core\class-simple-ajax-search.php:197
WordPress Hooks 5
actionplugins_loadedcore\class-simple-ajax-search.php:152
actionadmin_enqueue_scriptscore\class-simple-ajax-search.php:171
actionadmin_enqueue_scriptscore\class-simple-ajax-search.php:172
actionwp_enqueue_scriptscore\class-simple-ajax-search.php:190
actionwp_enqueue_scriptscore\class-simple-ajax-search.php:191
Maintenance & Trust

Simple Ajax Search Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedUnknown
PHP min version5.2.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Simple Ajax Search Developer Profile

pablocianes

4 plugins · 260 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Ajax Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-ajax-search/public/css/simple-ajax-search-public.css/wp-content/plugins/simple-ajax-search/public/js/simple-ajax-search-public.js
Script Paths
/wp-content/plugins/simple-ajax-search/public/js/simple-ajax-search-public.js
Version Parameters
simple-ajax-search/public/css/simple-ajax-search-public.css?ver=simple-ajax-search/public/js/simple-ajax-search-public.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Simple Ajax Search