Wp Search Url Security & Risk Analysis

wordpress.org/plugins/wp-search-url

This plugin change default wordpres ?s=swadesh search URLs to the /search/swadesh .

10 active installs v2.0 PHP + WP 3.3+ Updated Jul 13, 2015
custom-searchredirectsearch-urlwp-search-url
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wp Search Url Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Search Url has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "wp-search-url" v2.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unsanitized taint flows, or file operations is highly commendable. Furthermore, the plugin demonstrates good practices by correctly implementing nonce checks and ensuring all SQL queries utilize prepared statements. The complete lack of identified vulnerabilities in its history, including no past CVEs, suggests a commitment to security and a low likelihood of introducing significant security flaws.

While the static analysis reveals no immediate code-level risks, the extremely limited attack surface (zero AJAX handlers, REST API routes, shortcodes, or cron events) makes it difficult to fully assess the plugin's security in a real-world scenario. The absence of capability checks on the identified nonce check, although not a direct flaw given the minimal attack surface, could be a point of concern if new entry points were ever introduced. Overall, the plugin appears robust and secure in its current state, but its limited functionality means its security can be difficult to fully validate without more interaction points.

Based on the provided data, the plugin "wp-search-url" v2.0 appears to be very secure. The vulnerability history being entirely clean is a significant positive indicator. The static analysis shows no dangerous code patterns, and all identified code paths are handled with security best practices like prepared statements and output escaping. The presence of a nonce check is also a good sign. The lack of any identified issues or past vulnerabilities suggests a well-maintained and secure plugin.

Vulnerabilities
None known

Wp Search Url Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wp Search Url Release Timeline

vreadme.txt
vwp-search-url.php
Code Analysis
Analyzed Apr 16, 2026

Wp Search Url Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wp_config_url_page (wp-search-url.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wp Search Url Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuwp-search-url.php:12
actiontemplate_redirectwp-search-url.php:92
Maintenance & Trust

Wp Search Url Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 13, 2015
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Wp Search Url Developer Profile

swadeshswain

7 plugins · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wp Search Url

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-table
Data Attributes
name='searchurl'value='yes'value='no'checked="checked"
FAQ

Frequently Asked Questions about Wp Search Url