
WP Fastest Site Search Security & Risk Analysis
wordpress.org/plugins/wp-fastest-site-searchReplace the default search with ExpertRec's powerful and fully customizable WordPress search plugin.
Is WP Fastest Site Search Safe to Use in 2026?
Generally Safe
Score 100/100WP Fastest Site Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-fastest-site-search plugin exhibits a generally good security posture, with no known vulnerabilities or critical taint flows detected. The code analysis reveals that all output is properly escaped, which is a significant strength. Furthermore, the plugin does not bundle any libraries, reducing the risk of using outdated or vulnerable third-party code. The absence of known CVEs and a clear vulnerability history further contributes to its positive security profile.
However, there are notable areas for concern. The plugin has a substantial attack surface, with 66 entry points identified, one of which lacks permission callbacks. This unprotected REST API route is a significant risk, as it could potentially be exploited by unauthenticated users. Additionally, the complete absence of nonce checks and capability checks across its code signals a potential for privilege escalation or unauthorized actions if other weaknesses are discovered or introduced. While the plugin uses prepared statements for a majority of its SQL queries, the presence of raw SQL without preparation for some queries could lead to SQL injection vulnerabilities.
In conclusion, while the plugin demonstrates good practices in output escaping and a clean vulnerability history, the unprotected REST API endpoint, lack of authorization checks (nonces and capabilities), and some raw SQL queries represent significant security weaknesses that need to be addressed to improve its overall security posture.
Key Concerns
- REST API route without permission callbacks
- No nonce checks
- No capability checks
- SQL queries without prepared statements
WP Fastest Site Search Security Vulnerabilities
WP Fastest Site Search Release Timeline
WP Fastest Site Search Code Analysis
SQL Query Safety
Output Escaping
WP Fastest Site Search Attack Surface
REST API Routes 65
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
WP Fastest Site Search Maintenance & Trust
Maintenance Signals
Community Trust
WP Fastest Site Search Alternatives
Audible Site Search
audible-site-search
Audible Site Search adds voice-powered search and AJAX search suggestions to your WordPress site.
Ivory Search – WordPress Search Plugin
add-search-to-menu
Advanced WordPress custom search plugin. Provides Search Form Customizer, WooCommerce Search, AJAX Search & Live Search support!
FiboSearch – Ajax Search for WooCommerce
ajax-search-for-woocommerce
The most popular WooCommerce product search plugin. Gives your users a well-designed advanced AJAX search bar with live search suggestions.
WP Extended Search
wp-extended-search
Extend search functionality to search in selected post meta, taxonomies, post types, and all authors.
Advance Product Search- Voice & Ajax Search for WooCommerce
th-advance-product-search
Advanced Product Search boosts your store search with instant AJAX results, live suggestions, and smart category filtering, helping customers find pro …
WP Fastest Site Search Developer Profile
1 plugin · 100 total installs
How We Detect WP Fastest Site Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fastest-site-search/assets/css/expertrecsearch-admin.css/wp-content/plugins/wp-fastest-site-search/assets/js/expertrecsearch-admin.js/wp-content/plugins/wp-fastest-site-search/includes/class-expertrecsearch-loader.php/wp-content/plugins/wp-fastest-site-search/public/class-expertrecsearch-public.php/wp-content/plugins/wp-fastest-site-search/includes/class-expertrecsearch.php/wp-content/plugins/wp-fastest-site-search/hooks/expertrecsearch-rest.php/wp-content/plugins/wp-fastest-site-search/includes/class-expertrecsearch-client.phpexpertrecsearch-admin.css?ver=expertrecsearch-admin.js?ver=HTML / DOM Fingerprints
expertrecsearch-admin-wrap<!-- Expertrec Search Admin --><!-- Expertrec Search --><!-- end expertrecsearch-admin-wrap -->data-site-iddata-plugin-versionexpertrec_admin_objectexpertrec_public_object/wp-json/expertrecsearch/v1/settings/wp-json/expertrecsearch/v1/sync