
VK Filter Search Security & Risk Analysis
wordpress.org/plugins/vk-filter-searchThis plugin allows you to add a search function as a block to narrow down your search by category, tag, custom post type, keyword, etc.
Is VK Filter Search Safe to Use in 2026?
Generally Safe
Score 99/100VK Filter Search has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "vk-filter-search" v2.18.3.0 exhibits a mixed security posture. Static analysis reveals strong adherence to secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. The attack surface is also managed well, with no unprotected entry points identified. However, the absence of nonce checks across all entry points is a significant concern, as it leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks, especially given the presence of shortcodes which can be exploited to trigger actions without user consent.
The vulnerability history is particularly concerning, with two known CVEs, one of which remains unpatched. Both known vulnerabilities are of medium severity and fall under Cross-Site Scripting (XSS). The presence of a recent unpatched medium severity XSS vulnerability, combined with the lack of nonce checks, suggests a pattern where input sanitization or output escaping might be insufficient in certain contexts, even though the overall static analysis indicates good escaping. This highlights a potential blind spot in the plugin's security.
In conclusion, while the plugin demonstrates good foundational security practices in its code, the unpatched XSS vulnerability and the absence of nonce checks are critical weaknesses. The pattern of XSS vulnerabilities suggests that further rigorous testing and patching are necessary. Users should exercise caution until the unpatched CVE is resolved and nonce checks are implemented across all relevant functionalities.
Key Concerns
- Unpatched CVE
- No nonce checks
- Medium severity vulnerabilities (x2)
VK Filter Search Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
VK Filter Search <= 2.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
VK Filter Search <= 2.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
VK Filter Search Release Timeline
VK Filter Search Code Analysis
Output Escaping
Data Flow Analysis
VK Filter Search Attack Surface
Shortcodes 4
WordPress Hooks 38
Maintenance & Trust
VK Filter Search Maintenance & Trust
Maintenance Signals
Community Trust
VK Filter Search Alternatives
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Grow your organic traffic and AI visibility with powerful SEO tools, XML sitemaps, Schema automation, and built-in AI SEO, all in one place.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
SEOPress – AI SEO Plugin & On-site SEO
wp-seopress
WordPress SEO plugin with AI SEO metadata, schema, XML sitemap, redirections & Search Console. Privacy-first, white-label SEO. Now AI-ready.
VK Filter Search Developer Profile
8 plugins · 241K total installs
How We Detect VK Filter Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/style.css/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/editor.css/wp-content/plugins/vk-filter-search/inc/filter-search/build/style.css/wp-content/plugins/vk-filter-search/inc/filter-search/build/editor.css/wp-content/plugins/vk-filter-search/build/style.css/wp-content/plugins/vk-filter-search/build/editor.css/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/index.js/wp-content/plugins/vk-filter-search/inc/filter-search/build/index.js/wp-content/plugins/vk-filter-search/build/index.jsvk-filter-search/inc/dropdown-categories/build/style.css?ver=vk-filter-search/inc/dropdown-categories/build/editor.css?ver=vk-filter-search/inc/filter-search/build/style.css?ver=vk-filter-search/inc/filter-search/build/editor.css?ver=vk-filter-search/build/style.css?ver=vk-filter-search/build/editor.css?ver=vk-filter-search/inc/dropdown-categories/build/index.js?ver=vk-filter-search/inc/filter-search/build/index.js?ver=vk-filter-search/build/index.js?ver=HTML / DOM Fingerprints
vk_filter_search_formvk_filter_search_containervk_filter_search_input_groupdata-vkfs-label-accordiondata-vkfs-dropdown-optionsdata-vkfs-taxonomy-accordionvk_filter_search_params/wp-json/vk-filter-search/v1/search[vk_filter_search_form]