
Site Search 360 Security & Risk Analysis
wordpress.org/plugins/site-search-360Precise and fast search, autocompletion, and search suggestions for your WordPress page.
Is Site Search 360 Safe to Use in 2026?
Mostly Safe
Score 77/100Site Search 360 is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "site-search-360" v2.1.8 plugin exhibits a concerning security posture due to a combination of code analysis findings and its vulnerability history. While the absence of dangerous functions and file operations is positive, the significant portion of SQL queries lacking prepared statements (100%) is a major red flag for SQL injection vulnerabilities. Furthermore, only 26% of output is properly escaped, increasing the risk of Cross-Site Scripting (XSS) attacks. The presence of an unprotected AJAX handler, despite the plugin having fewer total entry points, presents a direct and easily exploitable attack vector.
The vulnerability history reinforces these concerns, with two known medium-severity CVEs, one of which remains unpatched. The historical pattern of CSRF and XSS vulnerabilities indicates a recurring weakness in input validation and output sanitization, which aligns with the current code analysis. The lack of capability checks on any entry points is also a significant weakness, potentially allowing unauthorized users to trigger plugin functionalities.
In conclusion, while the plugin has some strengths like a relatively small attack surface and a low number of external HTTP requests, the prevalence of unescaped output, unsanitized SQL queries, an unprotected AJAX handler, and an unpatched CVE paint a picture of a plugin that requires immediate attention to address critical security flaws. The vulnerability history suggests a pattern of neglect in secure coding practices, necessitating a thorough review and remediation.
Key Concerns
- Unpatched CVE
- 100% SQL queries without prepared statements
- Low output escaping percentage (26%)
- AJAX handler without auth checks
- No capability checks on entry points
- Flows with unsanitized paths
- Medium severity CVEs (2 total)
Site Search 360 Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Site Search 360 <= 2.1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Site Search 360 <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Site Search 360 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Site Search 360 Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 16
Maintenance & Trust
Site Search 360 Maintenance & Trust
Maintenance Signals
Community Trust
Site Search 360 Alternatives
Custom Search by BestWebSoft – WordPress Custom Search Plugin
custom-search-plugin
Add advanced custom search to your WordPress site. Search custom post types, taxonomies, and custom fields with full control over results.
SearchIQ – The Search Solution
searchiq
Our FREE plugin makes your website’s search fast and more relevant. searchIQ helps you to manage content more effectively with real-time analytics.
Swiftype Site Search Plugin for WordPress
swiftype-search
Fast, intelligent, and fully customizable search for your site.
Bing Custom Search for WordPress
wp-bing-search
Improve the search functionality on your site by using Bing Custom Search for WordPress.
WP Full Screen Search
wp-full-screen-search
This plugin converts default WordPress search to full screen search overlay form on your WordPress website.
Site Search 360 Developer Profile
10 plugins · 490 total installs
How We Detect Site Search 360
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-search-360/css/style.css/wp-content/plugins/site-search-360/js/search.js/wp-content/plugins/site-search-360/js/admin.js/wp-content/plugins/site-search-360/js/search.js/wp-content/plugins/site-search-360/js/admin.jssite-search-360/style.css?ver=site-search-360/search.js?ver=HTML / DOM Fingerprints
ss360-searchboxss360-searchbuttonss360-search-formss360-search-results-blockss360-search-menu-itemdata-ss360-includedata-ss360-excludedata-ss360-include-suggestdata-ss360-exclude-suggestdata-ss360-keep-placeholderdata-ss360<input class="ss360-searchbox"<button class="ss360-searchbutton"<form role="search" method="get" class="ss360-search-form search-form"<section role="search" class="ss360-search-form"