
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Security & Risk Analysis
wordpress.org/plugins/update-urlsQuick and Easy way to search all URLS, Content and replace them with new links and content in WordPress website.
Is Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Safe to Use in 2026?
Generally Safe
Score 100/100Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'update-urls' plugin v1.4.1 presents a generally good security posture with a limited attack surface and no recorded vulnerabilities. The presence of nonce and capability checks on its single AJAX handler indicates a conscious effort to implement basic security measures. The plugin also shows a reasonable approach to SQL queries with a significant percentage using prepared statements and a moderate number of output escaping implementations. However, the fact that only 50% of outputs are properly escaped is a notable concern, as it could lead to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data originates from untrusted sources. Furthermore, two flows with unsanitized paths in the taint analysis, while not classified as critical or high severity, warrant attention as they suggest potential issues with how file paths are handled, which could be exploited in specific scenarios. The plugin's vulnerability history being clear of any past issues is a positive indicator, but it's crucial to remember that this doesn't guarantee future safety, especially given the identified code signals that could become problematic without further hardening. Overall, while the plugin has strong foundations, the unescaped outputs and unsanitized paths are areas that require further investigation and remediation to ensure a robust security profile.
Key Concerns
- 50% of outputs not properly escaped
- 2 flows with unsanitized paths
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Security Vulnerabilities
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Attack Surface
AJAX Handlers 1
WordPress Hooks 18
Maintenance & Trust
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Maintenance & Trust
Maintenance Signals
Community Trust
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Alternatives
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Go Live Update Urls
go-live-update-urls
Change the domain on your site with one click.
Better Find and Replace – AI-Powered Suggestions
real-time-auto-find-and-replace
Search and replace text, images, URLs, footer credits, code blocks or jQuery-Ajax content in real time or in Database, easy user-interface
CM Search And Replace – Optimize content edits with a powerful search and replace tool
cm-on-demand-search-and-replace
Search and replace words, phrases, and HTML within your website posts and pages.
Easy Search Replace – Find & Replace Text/HTML/URLs, Remove Footer Credit
easy-search-replace
Real-time search & replace for text, HTML, and URLs. Target elements, post types/IDs/URLs. Safely remove footer credit no database changes.
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links Developer Profile
14 plugins · 31K total installs
How We Detect Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/update-urls/lite/dist/styles/app.css/wp-content/plugins/update-urls/lite/dist/styles/update-urls-admin.css/wp-content/plugins/update-urls/lite/dist/scripts/app.js/wp-content/plugins/update-urls/lite/dist/scripts/update-urls-admin.js/wp-content/plugins/update-urls/lite/dist/scripts/app.js/wp-content/plugins/update-urls/lite/dist/scripts/update-urls-admin.jsupdate-urls/lite/dist/styles/app.css?ver=update-urls/lite/dist/styles/update-urls-admin.css?ver=update-urls/lite/dist/scripts/app.js?ver=update-urls/lite/dist/scripts/update-urls-admin.js?ver=HTML / DOM Fingerprints
uuParams