
WPSOLR Search — WordPress Search Plugin Security & Risk Analysis
wordpress.org/plugins/wpsolr-freeEnterprise WordPress search plugin. Post types Search, WooCommerce Search, Live Search, Filters, Facets, Recommendations.
Is WPSOLR Search — WordPress Search Plugin Safe to Use in 2026?
Generally Safe
Score 98/100WPSOLR Search — WordPress Search Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The wpsolr-free plugin v24.4 exhibits a generally good security posture with several strengths, including a high percentage of SQL queries using prepared statements and excellent output escaping. The taint analysis also revealed no critical or high-severity vulnerabilities, indicating robust handling of potentially malicious input within the analyzed flows. The plugin also demonstrates a good number of nonce and capability checks.
However, there are notable areas of concern. The presence of two AJAX handlers without authentication checks represents a significant attack vector. While the taint analysis didn't flag issues, the lack of authorization on these entry points means an attacker could potentially trigger unintended actions. The plugin's vulnerability history, while currently showing no unpatched high-severity issues, does list one high-severity CVE in its past, which suggests a historical tendency towards vulnerabilities that require careful attention.
In conclusion, wpsolr-free v24.4 has strong internal code security practices. The primary weakness lies in the exposed AJAX endpoints, which could be exploited if not properly secured at the application level. While the past CVE is resolved, it serves as a reminder for ongoing vigilance. Overall, the plugin is reasonably secure but requires attention to the unauthenticated AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- High-severity CVE in vulnerability history
- Bundled outdated library (Select2 v3.5.4)
WPSOLR Search — WordPress Search Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPSolr <= 24.0 - Cross-Site Request Forgery to Privilege Escalation
WPSOLR Search — WordPress Search Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WPSOLR Search — WordPress Search Plugin Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 43
Maintenance & Trust
WPSOLR Search — WordPress Search Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WPSOLR Search — WordPress Search Plugin Alternatives
Advanced Product Search For WooCommerce
advanced-product-search-for-woo
Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.
Ajax Product Search for WooCommerce (ProSearch)
modern-product-search-for-woocommerce
Smart, fast, and accurate Ajax Product Search for WooCommerce with live results, fuzzy matching, and instant product suggestions.
DooSearch – Ajax Search & Filters for WooCommerce
doosearch-ajax-search-for-woo
A blazing-fast WooCommerce product search plugin with AJAX and live filters to boost conversions.
Dragonfly – Advanced Live Search
dragonfly
Search Any Post Type Or Taxonomy
FtlCommerce – Instant Product Search
ftlcommerce-instant-product-search
Lightning-fast, client-side fuzzy search for WooCommerce products. Zero server delays, instant results, advanced filtering.
WPSOLR Search — WordPress Search Plugin Developer Profile
1 plugin · 90 total installs
How We Detect WPSOLR Search — WordPress Search Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpsolr-free/wpsolr.inc.phpwpsolr-free/wpsolr-free.php?ver=wpsolr-free.php?ver=HTML / DOM Fingerprints
wpsolr_facet_skin_nonewpsolr_facet_radioboxwpsolr_facet_selectwpsolr_facet_class_wpsolr_permalinkwpsolr_localize_script_layout