SniffPress Security & Risk Analysis

wordpress.org/plugins/sniffpress

A powerful search tool that helps developers quickly find text strings within theme and plugin files.

20 active installs v1.1 PHP 7.4+ WP 5.6+ Updated Dec 23, 2025
code-searchdeveloper-toolsfile-searchsearchstring-search
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SniffPress Safe to Use in 2026?

Generally Safe

Score 100/100

SniffPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin 'sniffpress' v1.1 exhibits a generally strong security posture based on the provided static analysis. It has a very limited attack surface, with only one AJAX handler, and critically, this entry point includes necessary authentication and capability checks, along with a nonce check. The code demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of output is properly escaped, minimizing the risk of cross-site scripting vulnerabilities. The absence of dangerous functions, external HTTP requests, and bundled libraries further contributes to its secure profile. Furthermore, the plugin has no recorded vulnerability history, indicating a stable and likely well-maintained codebase. The taint analysis showing zero unsanitized paths reinforces the confidence in its secure handling of data flows. While the presence of a file operation is noted, without further context or analysis, it's not flagged as an immediate risk. The strengths of this plugin lie in its robust authentication and sanitization practices for its limited entry points.

Key Concerns

  • Single file operation detected.
Vulnerabilities
None known

SniffPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SniffPress Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Mar 16, 2026

SniffPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
71 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped79 total outputs
Attack Surface

SniffPress Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_sniffp_searchincludes\class-sniffpress-search.php:11
WordPress Hooks 3
actionadmin_menuadmin\class-sniffpress-admin.php:8
actionadmin_enqueue_scriptsadmin\class-sniffpress-admin.php:9
actionplugins_loadedsniffpress.php:59
Maintenance & Trust

SniffPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 23, 2025
PHP min version7.4
Downloads483

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

SniffPress Developer Profile

wpwebguru

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SniffPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sniffpress/assets/css/style.css/wp-content/plugins/sniffpress/assets/js/script.js
Script Paths
/wp-content/plugins/sniffpress/assets/js/script.js
Version Parameters
sniffpress-csssniffp-script

HTML / DOM Fingerprints

CSS Classes
sniffpress-containersniffpress-formform-groupform-labelsearch-string-containersniffpress-multiselectlocation-select-containerlocation-actions+21 more
Data Attributes
data-action-url
JS Globals
sniffpWpVars
FAQ

Frequently Asked Questions about SniffPress