
Advanced All in One Admin Search by WP Spotlight Security & Risk Analysis
wordpress.org/plugins/wp-spotlight-searchAdvanced All in One Admin Search by WP Spotlight Global Search is a powerful quick navigation plugin for WordPress Dashboard - it is an advancement of …
Is Advanced All in One Admin Search by WP Spotlight Safe to Use in 2026?
Generally Safe
Score 99/100Advanced All in One Admin Search by WP Spotlight has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "wp-spotlight-search" v1.1.2 exhibits a mixed security posture. While the static analysis shows a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and a decent number of capability and nonce checks, several critical concerns remain. The presence of the `unserialize` function is a significant red flag, as it can lead to Remote Code Execution (RCE) if used with untrusted input. Furthermore, all SQL queries in the code are executed without prepared statements, opening the door to SQL injection vulnerabilities. The plugin also has a 50% rate of unescaped output, which could lead to Cross-Site Scripting (XSS) attacks.
The vulnerability history shows a past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF) vulnerability. Although this is marked as unpatched, the fact that it was a medium severity and is in the past indicates a potential weakness in input validation or access control. Coupled with the static analysis findings of potential RCE and SQL injection, the plugin requires careful scrutiny. The low number of entry points is a strength, but the identified dangerous functions and lack of secure coding practices in data handling (SQL, unserialize, output escaping) present significant risks.
Key Concerns
- Dangerous function unserialize present
- SQL queries lack prepared statements
- Output escaping not fully implemented
- Past medium severity CVE (CSRF)
Advanced All in One Admin Search by WP Spotlight Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced All in One Admin Search by WP Spotlight <= 1.1.1 - Cross-Site Request Forgery
Advanced All in One Admin Search by WP Spotlight Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Advanced All in One Admin Search by WP Spotlight Attack Surface
WordPress Hooks 8
Maintenance & Trust
Advanced All in One Admin Search by WP Spotlight Maintenance & Trust
Maintenance Signals
Community Trust
Advanced All in One Admin Search by WP Spotlight Alternatives
Admin Menu Search
admin-menu-search
Admin Menu Search adds a search box filter to the top of the WordPress Admin Menu so you can easily locate items on sites with lots of menus.
WP Editarea
wp-editarea
WP Editarea turns your Oldschool textarea code editor in Wordpress Dashboard (plugin/theme editor) into a fancy realtime highlighted code editor using …
Dashboard & Menu Cleaner (Quick Menu Finder)
dashboard-menus-cleaner
This plugin will help you hide the default WordPress dashboard widgets like Incoming Links, etc.
Dashboard User profile Detais-(DUPD)
dashboard-user-profile-detais-dupd
A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.
Plugin
dashboard-user-profile-dup
A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.
Advanced All in One Admin Search by WP Spotlight Developer Profile
1 plugin · 1K total installs
How We Detect Advanced All in One Admin Search by WP Spotlight
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-spotlight-search/assets/js/keyboardShortcut.js/wp-content/plugins/wp-spotlight-search/assets/js/init.js/wp-content/plugins/wp-spotlight-search/assets/js/semantic.min.js/wp-content/plugins/wp-spotlight-search/assets/css/semantic.min.css/wp-content/plugins/wp-spotlight-search/assets/css/settings.csswp-content/plugins/wp-spotlight-search/assets/js/keyboardShortcut.jswp-content/plugins/wp-spotlight-search/assets/js/init.jswp-content/plugins/wp-spotlight-search/assets/js/semantic.min.jswp-spotlight-search/assets/js/keyboardShortcut.js?ver=wp-spotlight-search/assets/js/init.js?ver=wp-spotlight-search/assets/js/semantic.min.js?ver=wp-spotlight-search/assets/css/semantic.min.css?ver=wp-spotlight-search/assets/css/settings.css?ver=HTML / DOM Fingerprints
wp_spotlight_search_boxid="wp_spotlight_search_box"wp_spotlight_full_menu