
Wavinai Search Security & Risk Analysis
wordpress.org/plugins/wavinai-searchEnhance your WooCommerce store with Wavinai Search, the smart and customizable search solution that transforms the way your customers shop.
Is Wavinai Search Safe to Use in 2026?
Generally Safe
Score 100/100Wavinai Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wavinai-search" plugin version 1.2.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent practices, with 100% of outputs properly escaped and 97% of SQL queries utilizing prepared statements. There are no identified dangerous functions or external HTTP requests, and the plugin has no recorded vulnerability history, suggesting a robust development and maintenance process. The limited attack surface, consisting of a single shortcode, is also a positive indicator.
However, a notable concern is the complete absence of nonce checks across all identified entry points, despite the presence of capability checks. While the static analysis shows no critical or high-severity taint flows and no direct SQL injection risks from raw SQL, the lack of nonces leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality can be exploited maliciously. The presence of file operations, though only one, warrants careful consideration in conjunction with the lack of nonce checks. Overall, the plugin is well-coded with many security best practices, but the missing nonce checks represent a significant, albeit addressable, weakness that could be exploited.
Key Concerns
- Missing nonce checks on entry points
Wavinai Search Security Vulnerabilities
Wavinai Search Code Analysis
SQL Query Safety
Output Escaping
Wavinai Search Attack Surface
Shortcodes 1
WordPress Hooks 25
Maintenance & Trust
Wavinai Search Maintenance & Trust
Maintenance Signals
Community Trust
Wavinai Search Alternatives
No alternatives data available yet.
Wavinai Search Developer Profile
7 plugins · 60 total installs
How We Detect Wavinai Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wavinai-search/dist/css/wavinai-search.css/wp-content/plugins/wavinai-search/dist/js/wavinai-search.js/wp-content/plugins/wavinai-search/dist/css/wavinai-search-admin-settings.css/wp-content/plugins/wavinai-search/dist/js/wavinai-search-admin-settings.js/wp-content/plugins/wavinai-search/dist/js/wavinai-search.js/wp-content/plugins/wavinai-search/dist/js/wavinai-search-admin-settings.jswavinai-search/dist/css/wavinai-search.css?ver=wavinai-search/dist/js/wavinai-search.js?ver=wavinai-search/dist/css/wavinai-search-admin-settings.css?ver=wavinai-search/dist/js/wavinai-search-admin-settings.js?ver=HTML / DOM Fingerprints
wvn-search-wrapperwvn-search-inputwvn-search-buttonwvn-search-suggestionswvn-search-suggestion-itemwavinai-search-admin-settingswvn-product-count-desktopwvn-product-count-tablet+2 more<!-- Wavinai Search Plugin --><!-- Start Wavinai Search Admin Settings --><!-- End Wavinai Search Admin Settings -->data-wvn-search-apiWavinaiSearchConfig/wp-json/wavinai-search/v1/products[wavinai_search][wavinai_search_form]