
WP FILE SEARCH Security & Risk Analysis
wordpress.org/plugins/wp-file-searchWP SEARCH FILE enables searching on pdf, docx and odt files
Is WP FILE SEARCH Safe to Use in 2026?
Generally Safe
Score 85/100WP FILE SEARCH has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-file-search" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history is a significant positive indicator, suggesting the developers have a good track record of addressing security issues. The static analysis reveals no critical or high severity taint flows, nor any dangerous functions, which are excellent signs.
However, there are a few areas for potential concern. While the number of SQL queries is low, 75% using prepared statements means 25% are not, posing a moderate risk of SQL injection if those queries handle user input without proper sanitization. Similarly, only 50% of output is properly escaped, leaving a chance for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled. The presence of one cron event without explicit mention of an authorization check could also be a potential entry point if not secured properly.
Overall, the plugin appears to be built with security in mind, with a minimal attack surface and the use of nonces and capability checks. The lack of historical vulnerabilities is reassuring. The main areas to monitor are the SQL queries and output escaping, as these represent the most likely avenues for exploitation based on the static analysis. Further investigation into the specific implementation of the cron event and the unescaped outputs would be beneficial.
Key Concerns
- Raw SQL query without prepared statement
- Unescaped output
- Cron event potentially without auth check
- Bundled outdated library (TCPDF v1.0)
WP FILE SEARCH Security Vulnerabilities
WP FILE SEARCH Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP FILE SEARCH Attack Surface
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
WP FILE SEARCH Maintenance & Trust
Maintenance Signals
Community Trust
WP FILE SEARCH Alternatives
File Download
file-download
A simple file download widget for frontend interface. Lets your visitors download brochures etc.
Ivory Search – WordPress Search Plugin
add-search-to-menu
Advanced WordPress custom search plugin. Provides Search Form Customizer, WooCommerce Search, AJAX Search & Live Search support!
FileBird Document Library
filebird-document-library
Create WordPress document library using FileBird and Gutenberg or any WordPress page builder.
Document Gallery – Display PDF Gallery from Many Folders
catfolders-document-gallery
Display WordPress PDF gallery and file gallery from folder. Comes with a clean, searchable & sortable list/grid layout.
WP Fast Total Search – The Power of Indexed Search
fulltext-search
Extends the default fulltext search with relevance, jet speed and ability to search any posts, metadata, taxonomy, shortcode content and more data.
WP FILE SEARCH Developer Profile
1 plugin · 100 total installs
How We Detect WP FILE SEARCH
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-file-search/css/wp-file-search-admin.css/wp-content/plugins/wp-file-search/js/wp-file-search-admin.js/wp-content/plugins/wp-file-search/js/wp-file-search-admin.jswp-file-search/css/wp-file-search-admin.css?ver=wp-file-search/js/wp-file-search-admin.js?ver=HTML / DOM Fingerprints
data-wp-file-search-search-btndata-wp-file-search-search-inputdata-wp-file-search-search-results[wp_file_search]