shouldiuse.io

Categories

VERDICT

Relevanssi Review

Depends

Should I use Relevanssi?

A Better Search for WordPress — replaces the default search - relevanssi.com

· 23 hours ago

Buy the free version if default WordPress search fails you on a content-heavy or WooCommerce site. Skip if your site is small or you can't commit to patching plugin CVEs within days.

Confidence

Medium. Based on 20+ public sources; several review snippets were truncated, limiting verbatim user quotes.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
PremiumGuess: ~$99/yr (resellers list $59)

Best for

  • Content-heavy WordPress blogs
  • WooCommerce stores
  • Multisite networks (Premium)
  • Budget-conscious site owners

Not for

  • Small sites where default WordPress search already works
  • Teams that can't patch plugins within days of a CVE
  • Anyone wanting hands-off hosted SaaS search
  • Non-WordPress platforms

Gotchas - check before you buy

high

Unauthenticated SQLi/XSS CVEs in 2025–2026; unpatched sites are exposed.

medium

Premium has no free trial; you commit before testing relevance on your own content.

low

Cheap '$59' licenses circulate via GPL reseller sites — unofficial and unsupported.

low

Indexing large catalogs grows database load; check the vendor performance FAQ first.

Pros and cons

Pros

  • Free version replaces default WordPress search with better relevance.
  • Strong reputation for WordPress and WooCommerce product search.
  • Premium adds multisite search and user profile search.
  • Actively maintained — new releases shipped September 2026.
  • 100K+ installs with 4.8/5 rating.

Cons

  • Repeated unauthenticated SQL injection and XSS vulnerabilities through 2024–2026.
  • No Premium free trial — pay before testing on your content.
  • Plugin author himself says many sites shouldn't bother with search enhancement.
  • Search indexing adds database load and speed considerations on big sites.

Sources & method

- 10 sources - Active CVE history: unauthenticated SQL injection and stored XSS in free and Premium versions, 2024–2026. Patch fast or think twice on sensitive sites.

official x3review x4security x2news x1
  • Unauthenticated stored XSS (≤4.28.3), Comment content could inject scripts into search results for visitors.
  • Unauthenticated SQL injection (4.24.4), Reported via Patchstack, May 2025; no login required.
  • Premium unauthenticated SQL injection (2.27.4), Premium 2.27.4 had unauthenticated SQL injection, May 2025.
  • CVE-2026-15941, SQL injection vulnerability in the Relevanssi plugin, August 2026.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 4/5. Capable free core; Premium costs upfront
  • Ease of use: 3/5. Needs indexing and settings tuning after install
  • Feature depth: 4/5. Premium adds multisite and user profile search
  • Support quality: 3/5. Frequent 2026 releases; manual and knowledge base
  • Security posture: 1/5. Repeated unauthenticated SQLi and XSS 2024–2026
  • 4.8/5 WordPress.org rating 100K+ active installs
  • Free Starting price Premium is paid, no free trial
  • 100K+ Active installs WordPress.org repository
  • 5+ Security advisories CVEs 2024–2026, incl. SQLi and XSS

Pricing

Free

$0

  • Replaces default WP search
  • Better relevance and indexing

Premium

Guess: ~$99/yr (resellers list $59)

  • Multisite search
  • User profile search
  • No free trial

Security

Active CVE history: unauthenticated SQL injection and stored XSS in free and Premium versions, 2024–2026.

  • Unauthenticated stored XSS (≤4.28.3)Comment content could inject scripts into search results for visitors.⁶
  • Unauthenticated SQL injection (4.24.4)Reported via Patchstack, May 2025; no login required.⁷

Patch fast or think twice on sensitive sites.

  • Premium unauthenticated SQL injection (2.27.4)Premium 2.27.4 had unauthenticated SQL injection, May 2025.
  • CVE-2026-15941SQL injection vulnerability in the Relevanssi plugin, August 2026.

What users say

Community reviews call it the best WordPress/WooCommerce search plugin, and WordPress.org shows 4.8/5 across 100K+ installs.

Companies that use it

  • Temple University
Full analysis

Based on 20+ public sources; several review snippets were truncated, limiting verbatim user quotes.

Great free search fix for content-heavy WordPress sites — but 2024–2026 CVE streak means you must patch fast. Small sites: skip.

Methodology

Based on 20+ public sources; several review snippets were truncated, limiting verbatim user quotes.

Read how a report is made.

Sources

  1. official
  2. official
  3. official
  4. review
  5. review
  6. security
  7. security
  8. news
  9. review
  10. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.