Relevanssi Premium

Use with caution

Confidence: Medium
This recommendation applies to version 1.10.13 of this plugin, but the most recent version is 1.12.1. These findings may no longer be correct.

This plugin takes an idiosyncratic approach to SQL generation. It contains a large number of long and complicated SQL queries and there is no organised or methodical approach to generating them safely.

This plugin also has a history of broken releases, including one which contained malicious code added to the distribution after the author’s website was hacked in July 2013. The release containing malicious code was, however, promptly fixed and an updated version released.

Failure criteria

  • Execution of unprepared SQL statements
  • Poor architecture
  • Failure to use available core functionality

