
WP Find And Replace Security & Risk Analysis
wordpress.org/plugins/wp-find-and-replaceFind and replace content into pages and posts
Is WP Find And Replace Safe to Use in 2026?
Generally Safe
Score 85/100WP Find And Replace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-find-and-replace" v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations is commendable. Furthermore, all SQL queries are protected by prepared statements, and the presence of nonce and capability checks suggests good development practices in place to prevent common WordPress vulnerabilities. The taint analysis revealing no unsanitized paths further reinforces this positive assessment.
However, a key concern arises from the output escaping. With 67% of outputs properly escaped, there's a 33% chance of unescaped output, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. While the plugin has no recorded vulnerability history, this doesn't guarantee future immunity. The overall risk is low, primarily stemming from the potential for unescaped output, which can be mitigated through careful implementation of the remaining output handling.
Key Concerns
- Potential for unescaped output
WP Find And Replace Security Vulnerabilities
WP Find And Replace Release Timeline
WP Find And Replace Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Find And Replace Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Find And Replace Maintenance & Trust
Maintenance Signals
Community Trust
WP Find And Replace Alternatives
Search and Replace
search-replace
Search and replace content into pages and posts
Quick Search & Replace for Block Page Editor
search-replace-for-block-page-editor
The "Quick Search & Replace for Block Page Editor" plugin allows you to efficiently search and replace content within individual pages i …
Search Exclude
search-exclude
Hide any post or page from the search results.
Search in Place
search-in-place
Search in Place improves blog search by displaying query results in real time. It displays the results dynamically as you enter the search criteria.
WP Hide Post — Hide Posts, Pages, Custom Post Types, and Control Products Visibility for WooCommerce
wp-post-hide
Want to hide WordPress posts, pages, custom post types, and WooCommerce products from the homepage, archives, search, RSS, and REST API? Check out WP …
WP Find And Replace Developer Profile
2 plugins · 300 total installs
How We Detect WP Find And Replace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-find-and-replace/css/style.csswp-find-and-replace/css/style.css?ver=