WP Google Search Security & Risk Analysis

wordpress.org/plugins/wp-google-search

This plugin gives a very simple way to integrate Google Search into your WordPress site.

6K active installs v1.1.0 PHP + WP 3.7+ Updated Aug 3, 2022
googlegoogle-custom-searchgoogle-searchscewp-google-search
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Google Search Safe to Use in 2026?

Generally Safe

Score 85/100

WP Google Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wp-google-search plugin v1.1.0 exhibits a generally good security posture with no known vulnerabilities or critical code signals. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive indicator. However, the analysis reveals a significant concern regarding output escaping, with only 29% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being rendered to the browser. While there are no active taint flows or immediate critical risks identified, the lack of comprehensive output escaping represents a substantial weakness that could be exploited. The plugin's vulnerability history is clean, suggesting a history of secure development, but this should not overshadow the present concern with output sanitization.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

WP Google Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Google Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped45 total outputs
Attack Surface

WP Google Search Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wp_google_search] wp-google-search.php:101
[wp_google_searchbox] wp-google-search.php:102
WordPress Hooks 4
actionadmin_menuwgs-admin-page.php:6
actionadmin_initwgs-admin-page.php:7
actionwidgets_initwgs-widget.php:94
actioninitwp-google-search.php:48
Maintenance & Trust

WP Google Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 3, 2022
PHP min version
Downloads184K

Community Trust

Rating88/100
Number of ratings28
Active installs6K
Developer Profile

WP Google Search Developer Profile

WebshopLogic

4 plugins · 6K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Google Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-google-search/wgs.css/wp-content/plugins/wp-google-search/wgs2.css/wp-content/plugins/wp-google-search/wgs3.css
Script Paths
/wp-content/plugins/wp-google-search/assets/js/google_cse_v2.js
Version Parameters
wp-google-search/wgs.css?ver=wp-google-search/wgs2.css?ver=wp-google-search/wgs3.css?ver=wp-google-search/assets/js/google_cse_v2.js?ver=

HTML / DOM Fingerprints

CSS Classes
wgs_wrapper
HTML Comments
<!--20140423--><!-- You can use HTML5-valid div tags as long as you observe these guidelines: -->
Data Attributes
data-linktargetdata-resultsUrl
JS Globals
scriptParams
Shortcode Output
<div class="gcse-search"<div class="gcse-searchresults-only"<div class="gcse-searchbox-only"
FAQ

Frequently Asked Questions about WP Google Search