
VK Filter Search Security & Risk Analysis
wordpress.org/plugins/vk-filter-searchThis plugin allows you to add a search function as a block to narrow down your search by category, tag, custom post type, keyword, etc.
Is VK Filter Search Safe to Use in 2026?
Mostly Safe
Score 77/100VK Filter Search is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The plugin "vk-filter-search" v2.18.3.0 exhibits a mixed security posture. Static analysis reveals strong adherence to secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. The attack surface is also managed well, with no unprotected entry points identified. However, the absence of nonce checks across all entry points is a significant concern, as it leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks, especially given the presence of shortcodes which can be exploited to trigger actions without user consent.
The vulnerability history is particularly concerning, with two known CVEs, one of which remains unpatched. Both known vulnerabilities are of medium severity and fall under Cross-Site Scripting (XSS). The presence of a recent unpatched medium severity XSS vulnerability, combined with the lack of nonce checks, suggests a pattern where input sanitization or output escaping might be insufficient in certain contexts, even though the overall static analysis indicates good escaping. This highlights a potential blind spot in the plugin's security.
In conclusion, while the plugin demonstrates good foundational security practices in its code, the unpatched XSS vulnerability and the absence of nonce checks are critical weaknesses. The pattern of XSS vulnerabilities suggests that further rigorous testing and patching are necessary. Users should exercise caution until the unpatched CVE is resolved and nonce checks are implemented across all relevant functionalities.
Key Concerns
- Unpatched CVE
- No nonce checks
- Medium severity vulnerabilities (x2)
VK Filter Search Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
VK Filter Search <= 2.15.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
VK Filter Search <= 2.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
VK Filter Search Code Analysis
Output Escaping
Data Flow Analysis
VK Filter Search Attack Surface
Shortcodes 4
WordPress Hooks 38
Maintenance & Trust
VK Filter Search Maintenance & Trust
Maintenance Signals
Community Trust
VK Filter Search Alternatives
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Rank Math SEO is the best WordPress SEO plugin with the features of many SEO and AI SEO tools in a single package to help multiply your SEO traffic.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
VK Filter Search Developer Profile
8 plugins · 241K total installs
How We Detect VK Filter Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/style.css/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/editor.css/wp-content/plugins/vk-filter-search/inc/filter-search/build/style.css/wp-content/plugins/vk-filter-search/inc/filter-search/build/editor.css/wp-content/plugins/vk-filter-search/build/style.css/wp-content/plugins/vk-filter-search/build/editor.css/wp-content/plugins/vk-filter-search/inc/dropdown-categories/build/index.js/wp-content/plugins/vk-filter-search/inc/filter-search/build/index.js/wp-content/plugins/vk-filter-search/build/index.jsvk-filter-search/inc/dropdown-categories/build/style.css?ver=vk-filter-search/inc/dropdown-categories/build/editor.css?ver=vk-filter-search/inc/filter-search/build/style.css?ver=vk-filter-search/inc/filter-search/build/editor.css?ver=vk-filter-search/build/style.css?ver=vk-filter-search/build/editor.css?ver=vk-filter-search/inc/dropdown-categories/build/index.js?ver=vk-filter-search/inc/filter-search/build/index.js?ver=vk-filter-search/build/index.js?ver=HTML / DOM Fingerprints
vk_filter_search_formvk_filter_search_containervk_filter_search_input_groupdata-vkfs-label-accordiondata-vkfs-dropdown-optionsdata-vkfs-taxonomy-accordionvk_filter_search_params/wp-json/vk-filter-search/v1/search[vk_filter_search_form]