Xero Finder – Advanced Live Search & Instant Results for WordPress Security & Risk Analysis

wordpress.org/plugins/wpxero-search-filter

Xero Finder: a fast, powerful, and feature-rich live search solution for WordPress.

0 active installs v1.0.3 PHP 7.4+ WP 5.2+ Updated Jan 17, 2026
ajax-searchfilterlive-searchsearch
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xero Finder – Advanced Live Search & Instant Results for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Xero Finder – Advanced Live Search & Instant Results for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The wpxero-search-filter plugin v1.0.3 exhibits a seemingly strong security posture based on the provided static analysis, with no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication checks. The plugin also demonstrates good practices by overwhelmingly using prepared statements for its SQL queries and by avoiding dangerous functions, file operations, and external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history further suggests a well-maintained and secure plugin. However, a significant concern arises from the extremely low percentage (31%) of properly escaped output. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where unescaped user-supplied data could be rendered directly in the browser, potentially leading to malicious script execution. The lack of nonce checks and capability checks, while not immediately problematic given the apparent lack of entry points, could become a risk if any new entry points are introduced in future versions without proper security considerations. Overall, while the plugin's current attack surface is minimal and its SQL practices are solid, the poor output escaping is a critical weakness that requires immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Xero Finder – Advanced Live Search & Instant Results for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Xero Finder – Advanced Live Search & Instant Results for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
26 prepared
Unescaped Output
22
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared28 total queries

Output Escaping

31% escaped32 total outputs
Attack Surface

Xero Finder – Advanced Live Search & Instant Results for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsincludes\Admin\Enqueue.php:19
actionadmin_menuincludes\Admin\Menu.php:15
Maintenance & Trust

Xero Finder – Advanced Live Search & Instant Results for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 17, 2026
PHP min version7.4
Downloads220

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Xero Finder – Advanced Live Search & Instant Results for WordPress Developer Profile

WPXERO

6 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Xero Finder – Advanced Live Search & Instant Results for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpxero-search-filter/dist/frontend/css/wpxero-search-filter.css/wp-content/plugins/wpxero-search-filter/dist/frontend/js/wpxero-search-filter.js
Script Paths
/wp-content/plugins/wpxero-search-filter/dist/frontend/js/wpxero-search-filter.js
Version Parameters
wpxero-search-filter/dist/frontend/css/wpxero-search-filter.css?ver=wpxero-search-filter/dist/frontend/js/wpxero-search-filter.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpxero-search-filter-wrapperwpxero-search-filter-inputwpxero-search-filter-results-container
Data Attributes
data-wpxero-search-filter-id
JS Globals
wpxeroSearchDatawpxeroAdminData
REST Endpoints
/wp-json/wpxero/search/v1/settings/wp-json/wpxero/search/v1/search
Shortcode Output
[wpxero_search_filter]
FAQ

Frequently Asked Questions about Xero Finder – Advanced Live Search & Instant Results for WordPress