
Sitelinks Search Box Security & Risk Analysis
wordpress.org/plugins/sitelinks-search-boxAdds the JSON-LD schema.org markup for the "Google Sitelinks Search Box" on the homepage.
Is Sitelinks Search Box Safe to Use in 2026?
Generally Safe
Score 100/100Sitelinks Search Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "sitelinks-search-box" v1.5 plugin appears to be strong based on the provided static analysis and vulnerability history. There are no identified entry points into the application without authentication checks, no dangerous functions, and all SQL queries are handled using prepared statements. This indicates good development practices regarding common attack vectors. The absence of file operations, external HTTP requests, and the careful handling of data flow through taint analysis further bolster this positive assessment. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, and no history of unpatched issues, suggesting a well-maintained and secure codebase.
However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, this represents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data outputted by the plugin without proper sanitization can be exploited by attackers to inject malicious scripts into the user's browser. While the plugin exhibits strengths in data handling and entry point security, this lack of output escaping is a critical weakness that needs immediate attention. The absence of nonce and capability checks also, while not directly flagged in the provided data, could be a potential concern if any of the (currently zero) entry points were to be introduced in future updates without proper security controls. In conclusion, the plugin is secure in many areas but suffers from a critical flaw in output sanitization.
Key Concerns
- Output is not properly escaped
Sitelinks Search Box Security Vulnerabilities
Sitelinks Search Box Code Analysis
Output Escaping
Sitelinks Search Box Attack Surface
WordPress Hooks 2
Maintenance & Trust
Sitelinks Search Box Maintenance & Trust
Maintenance Signals
Community Trust
Sitelinks Search Box Developer Profile
28 plugins · 61K total installs
How We Detect Sitelinks Search Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<script type="application/ld+json">
</script>