Smart Admin Search Security & Risk Analysis

wordpress.org/plugins/smart-admin-search

This plugin adds a search engine to the WordPress dashboard.

30 active installs v1.5.1 PHP 5.6+ WP 5.0+ Updated Jan 3, 2026
admindashboardsearch
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Admin Search Safe to Use in 2026?

Generally Safe

Score 100/100

Smart Admin Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The smart-admin-search plugin version 1.5.1 exhibits a strong security posture based on the provided static analysis. There are no identified critical or high severity taint flows, no dangerous function calls, and all SQL queries are properly prepared, which are excellent security practices. The plugin also demonstrates good adherence to WordPress security standards with a significant number of capability checks and nonce checks in place. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment.

However, a small area of potential concern is the percentage of output escaping. While 82% is good, it means that approximately 18% of outputs are not properly escaped, which could lead to potential cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in those unescaped outputs. The analysis also shows no direct entry points like AJAX handlers or REST API routes without authentication, which significantly reduces the attack surface from external sources. The bundled Select2 library is noted, and while not explicitly flagged as a vulnerability, its version and potential for known issues would warrant further investigation in a real-world scenario.

In conclusion, smart-admin-search v1.5.1 appears to be a securely developed plugin with minimal identified risks. The primary area for improvement lies in ensuring all output is rigorously escaped to prevent potential XSS. The lack of any historical vulnerabilities is a strong indicator of ongoing security diligence, but vigilance regarding the remaining unescaped outputs is still recommended.

Key Concerns

  • Percentage of unescaped outputs is less than 100%
Vulnerabilities
None known

Smart Admin Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smart Admin Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
79 escaped
Nonce Checks
2
Capability Checks
10
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared1 total queries

Output Escaping

82% escaped96 total outputs
Attack Surface

Smart Admin Search Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\class-smart-admin-search.php:136
actionadmin_enqueue_scriptsincludes\class-smart-admin-search.php:151
actionadmin_enqueue_scriptsincludes\class-smart-admin-search.php:152
actionadmin_bar_menuincludes\class-smart-admin-search.php:153
actionadmin_footerincludes\class-smart-admin-search.php:154
actionadmin_noticesincludes\class-smart-admin-search.php:155
actionrest_api_initincludes\class-smart-admin-search.php:156
filterplugin_action_links_smart-admin-search/smart-admin-search.phpincludes\class-smart-admin-search.php:157
actionadmin_menuincludes\class-smart-admin-search.php:161
actionadmin_initincludes\class-smart-admin-search.php:162
filteradminmenuincludes\class-smart-admin-search.php:166
Maintenance & Trust

Smart Admin Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 3, 2026
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Smart Admin Search Developer Profile

Andrea Porotti

2 plugins · 330 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Admin Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-admin-search/admin/css/smart-admin-search-admin.css/wp-content/plugins/smart-admin-search/admin/js/smart-admin-search-admin.js/wp-content/plugins/smart-admin-search/admin/js/smart-admin-search-options.js/wp-content/plugins/smart-admin-search/assets/select2/select2.min.css/wp-content/plugins/smart-admin-search/assets/select2/select2.min.js/wp-content/plugins/smart-admin-search/assets/select2/i18n/en.js
Script Paths
/wp-content/plugins/smart-admin-search/admin/js/smart-admin-search-select2-fix.js/wp-content/plugins/smart-admin-search/admin/js/smart-admin-search-admin.js/wp-content/plugins/smart-admin-search/admin/js/smart-admin-search-options.js
Version Parameters
smart-admin-search/admin/css/smart-admin-search-admin.css?ver=smart-admin-search/admin/js/smart-admin-search-admin.js?ver=smart-admin-search/admin/js/smart-admin-search-options.js?ver=smart-admin-search/assets/select2/select2.min.css?ver=smart-admin-search/assets/select2/select2.min.js?ver=smart-admin-search/assets/select2/i18n/en.js?ver=

HTML / DOM Fingerprints

CSS Classes
sas-search-inputsas-search-results-containersas-no-results
HTML Comments
<!-- HTML --><!-- HEAD --><!-- BODY --><!-- SMART ADMINSEARCH -->+4 more
Data Attributes
data-sas-search-urldata-sas-noncedata-sas-search-results-url
JS Globals
sas_values
REST Endpoints
/smart-admin-search/v1/search
FAQ

Frequently Asked Questions about Smart Admin Search