WP Manifestindependent plugin directory
manifest / utilities / word-finder

Word Finder (Front End + Back End)

Find and replace text across a WordPress site's database and front end, with serialization-safe replacing and undo.

by cbanksbluecanopy · github.com/cbanksbluecanopy/word-finder

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/cbanksbluecanopy/word-finder/archive/refs/heads/main.zip

Word Finder for WordPress

Find every occurrence of a word or phrase across your WordPress site, on both the back end (database and theme files) and the front end (the pages as visitors see them), and see exactly where each match lives.

Features

Back end

Source What is searched
Posts Title, content and excerpt of posts, pages, custom post types, menu items and reusable blocks
Custom fields Post meta, including ACF, page-builder data and SEO plugin data
Options Site title, tagline, widgets, Customizer settings and plugin settings (transients are skipped)
Comments Comment text and author name
Terms Category, tag and custom taxonomy names and descriptions
Theme files (optional) Active theme and parent theme files (php, html, htm, js, css, json, txt), reported with line numbers

Front end

The tool fetches each public URL as a logged-out visitor and searches the rendered HTML. This catches text that only exists after rendering, such as theme template text, shortcode output and plugin-generated content.

URLs scanned:

  • The home page
  • All published, public, non-password-protected posts, pages and custom post types
  • Category, tag and other public taxonomy archives (non-empty terms)

For each page the tool reports whether the word appears in the visible text or only in the HTML source (an attribute, script, meta tag, etc.).

Search options

  • Case sensitive
  • Whole word only
  • Back end, front end and theme files can each be toggled on or off

Results table

Each match shows the area, where it was found, the field or line, the match count, a context snippet, and View and Edit links where available.

Requirements

  • WordPress 5.0+
  • PHP 7.2+
  • Administrator account (manage_options capability)

Installation

Option 1: As a plugin

  1. Create the folder wp-content/plugins/word-finder/.
  2. Save word-finder.php inside it.
  3. Activate Word Finder (Front End + Back End) under Plugins.

Option 2: As a snippet (Code Snippets, WPCode, etc.)

  1. Create a new PHP snippet.
  2. Paste the contents of word-finder.php, excluding the opening <?php line and the plugin header comment if your snippet plugin adds its own.
  3. Set it to run in the admin area and activate it.

Usage

  1. Go to Tools → Word Finder.
  2. Enter a word or phrase.
  3. Choose where to search and any options.
  4. Click Search.

Back-end results appear first. Front-end pages are then fetched in batches of 5, with a progress indicator, so large sites should not time out.

Configuration (filters)

Add these to your theme's functions.php or a snippet.

Filter Default Purpose
wf_sslverify true Return false on local or dev sites with self-signed SSL certificates
wf_max_urls 1000 Maximum number of posts scanned on the front end
wf_row_limit 5000 Maximum rows read per database source

Example:

// Local development with a self-signed certificate
add_filter( 'wf_sslverify', '__return_false' );

// Scan up to 3000 posts on the front end
add_filter( 'wf_max_urls', fn() => 3000 );

Notes and limitations

  • Draft, private and password-protected content appears only in back-end results, because visitors cannot see it.
  • Raw data matches: back-end matching runs on raw stored values, so a word inside a URL, an HTML attribute, a block comment or serialized data counts as a match.
  • wp-admin screens are not crawled. Only their stored data is searched.
  • Page caching: a wf_scan query parameter is added to each front-end request to help bypass page caches, but some caching layers may still serve cached copies.
  • Performance: the front-end scan makes one HTTP request per page. Run it during low-traffic periods on large sites.
  • Case sensitivity in the database prefilter depends on your table collation. Matches are then verified in PHP, so the Case sensitive and Whole word options are applied accurately to what is displayed.
  • Theme files: files larger than 1 MB and node_modules folders are skipped.

Security

  • Every request is protected by a nonce and requires the manage_options capability.
  • The browser never sends URLs to fetch. The URL list is built and stored server-side (per user, 1 hour), which prevents server-side request forgery (SSRF).
  • All results are inserted into the page as plain text, never as HTML.
  • The tool is read-only and never modifies your content.

File structure

word-finder/
├── word-finder.php   # The plugin / snippet
└── README.md         # This file

License

GPL-2.0-or-later, the same license as WordPress.