Talash – Advanced Search Plugin Security & Risk Analysis

wordpress.org/plugins/talash

Talash is an advanced search plugin for WordPress. Next Level of WordPress search experience.

0 active installs v1.1.8 PHP 5.6+ WP 4.9+ Updated Jan 7, 2022
advance-searchadvancedadvanced-searchsearchshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Talash – Advanced Search Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Talash – Advanced Search Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "talash" v1.1.8 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and file operations suggests careful coding practices. The high percentage of properly escaped output is also a positive indicator. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history implies a stable and potentially secure plugin.

However, there are areas for improvement. The presence of 8 AJAX handlers without explicit capability checks is a significant concern, as it leaves these entry points potentially vulnerable to unauthorized access if the underlying logic doesn't inherently protect them. While taint analysis found no issues, the lack of capability checks on these AJAX handlers could allow for unintended actions. The limited number of nonce checks (4) across 8 AJAX handlers also indicates a potential weakness.

In conclusion, while the plugin has a clean vulnerability history and good practices regarding SQL and output escaping, the lack of capability checks on a substantial number of AJAX handlers presents a notable risk. Addressing this oversight should be a priority to further harden the plugin's security.

Key Concerns

  • AJAX handlers without capability checks
  • Insufficient nonce checks on AJAX handlers
Vulnerabilities
None known

Talash – Advanced Search Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Talash – Advanced Search Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
10
92 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

90% escaped102 total outputs
Attack Surface

Talash – Advanced Search Plugin Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 8

authwp_ajax_talash_get_post_typespublic\classes\template-api.php:21
noprivwp_ajax_talash_get_post_typespublic\classes\template-api.php:22
authwp_ajax_talash_get_categoriespublic\classes\template-api.php:24
noprivwp_ajax_talash_get_categoriespublic\classes\template-api.php:25
authwp_ajax_talash_get_authorspublic\classes\template-api.php:27
noprivwp_ajax_talash_get_authorspublic\classes\template-api.php:28
authwp_ajax_get_search_resultspublic\classes\template-api.php:30
noprivwp_ajax_get_search_resultspublic\classes\template-api.php:31

Shortcodes 1

[talash-search] public\classes\talash-public.php:23
WordPress Hooks 8
actioncustomize_registeradmin\customizer\customizer.php:16
actioncustomize_preview_initadmin\customizer\customizer.php:26
actioncustomize_controls_print_stylesadmin\customizer\style.php:17
actionwp_headadmin\customizer\style.php:122
actionplugins_loadedinc\Talash.php:34
actionwp_enqueue_scriptspublic\classes\assets_meneger.php:16
actionwp_enqueue_scriptspublic\classes\assets_meneger.php:17
actionwp_enqueue_scriptspublic\classes\assets_meneger.php:18
Maintenance & Trust

Talash – Advanced Search Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJan 7, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Talash – Advanced Search Plugin Developer Profile

Keramot UL Islam

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Talash – Advanced Search Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/talash/assets/customizer/js/customizer.js/wp-content/plugins/talash/assets/vendors/date-range-picker/daterangepicker.min.css/wp-content/plugins/talash/assets/css/talash-main.css/wp-content/plugins/talash/assets/vendors/date-range-picker/moment.min.js/wp-content/plugins/talash/assets/vendors/date-range-picker/daterangepicker.js/wp-content/plugins/talash/assets/js/talash-main.js/wp-content/plugins/talash/assets/js/talash-main.min.js
Script Paths
/wp-content/plugins/talash/assets/customizer/js/customizer.js/wp-content/plugins/talash/assets/vendors/date-range-picker/moment.min.js/wp-content/plugins/talash/assets/vendors/date-range-picker/daterangepicker.js/wp-content/plugins/talash/assets/js/talash-main.js/wp-content/plugins/talash/assets/js/talash-main.min.js
Version Parameters
talash-customizer-jstalash-daterangepicker-csstalash-main-csstalash-momenttalash-daterangepickertalash-maintalash-main.min.js

HTML / DOM Fingerprints

CSS Classes
talash-headingsearch-barsearch-bar__inputunfoldsearch-bar__btn-searchtalash-advancedtalash-inner-popuptalash-result+20 more
Data Attributes
data-talash-id
JS Globals
talashPublicApi
Shortcode Output
[talash-search]
FAQ

Frequently Asked Questions about Talash – Advanced Search Plugin