Yuto – Meilisearch Integrator Security & Risk Analysis

wordpress.org/plugins/yuto

Turbocharge your website search with lightning-fast and hyper-relevant Meilisearch search engine

80 active installs v0.1.3 PHP 7.0+ WP 6.7+ Updated Aug 22, 2025
better-searchmeilisearchsearchyuto
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yuto – Meilisearch Integrator Safe to Use in 2026?

Generally Safe

Score 100/100

Yuto – Meilisearch Integrator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The yuto plugin v0.1.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by properly escaping all output and exclusively using prepared statements for SQL queries, which is commendable. The absence of dangerous functions, file operations, and critical taint flows further reinforces this positive assessment. Furthermore, the plugin has no recorded vulnerability history, suggesting a well-maintained and secure codebase to date.

However, the static analysis does highlight a few areas that warrant caution. The presence of 5 external HTTP requests without explicit context on their purpose or security implications is a potential concern. More significantly, the complete absence of nonce checks and capability checks across all entry points (even the single shortcode) represents a substantial security weakness. While the attack surface is currently small and there are no unprotected AJAX handlers or REST API routes, this lack of access control could become a serious vulnerability if the plugin's functionality expands or if the shortcode is exposed in a way that allows for unauthorized execution of its logic.

In conclusion, while yuto v0.1.3 is built on a solid foundation of secure coding principles, the lack of nonce and capability checks is a critical oversight. This leaves the plugin vulnerable to potential authorization bypasses or unintended actions if its shortcode is exploited. The external HTTP requests also warrant further investigation to ensure they are not introducing additional risks.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • External HTTP requests without security context
Vulnerabilities
None known

Yuto – Meilisearch Integrator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yuto – Meilisearch Integrator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

Yuto – Meilisearch Integrator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[yuto_autocomplete] inc\shortcodes\autocomplete.php:85
WordPress Hooks 11
filterplugin_action_linksinc\admin\plugin-action-links.php:43
filterplugin_row_metainc\admin\plugin-action-links.php:74
actionwp_after_insert_postinc\admin\post-handler.php:75
actionwp_trash_postinc\admin\post-handler.php:118
actionadmin_menuinc\admin\setting.php:30
actionadmin_enqueue_scriptsinc\admin\setting.php:99
actioninitinc\admin\setting.php:148
actioninitinc\block.php:17
actionwp_enqueue_scriptsinc\block.php:29
actionwp_loadedinc\Yuto.php:80
actionplugins_loadedyuto.php:42
Maintenance & Trust

Yuto – Meilisearch Integrator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 22, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings6
Active installs80
Developer Profile

Yuto – Meilisearch Integrator Developer Profile

Pono Press

4 plugins · 230 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yuto – Meilisearch Integrator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yuto/build/settings/index.css/wp-content/plugins/yuto/build/settings/index.js/wp-content/plugins/yuto/build/blocks/autocomplete
Script Paths
/wp-content/plugins/yuto/build/settings/index.js
Version Parameters
/wp-content/plugins/yuto/build/settings/index.js?ver=/wp-content/plugins/yuto/build/settings/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
yuto-settings
Data Attributes
data-placement
JS Globals
yutoAdminDatayutoViewData
REST Endpoints
/wp-json/yuto/v1/settings
Shortcode Output
[yuto_autocomplete enabledIndices
FAQ

Frequently Asked Questions about Yuto – Meilisearch Integrator