Word Finder (Front End + Back End)
Find and replace text across a WordPress site's database and front end, with serialization-safe replacing and undo.
by cbanksbluecanopy · github.com/cbanksbluecanopy/word-finder
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/cbanksbluecanopy/word-finder/archive/refs/heads/main.zipWord Finder for WordPress
Find every occurrence of a word or phrase across your WordPress site, on both the back end (database and theme files) and the front end (the pages as visitors see them), and see exactly where each match lives.
Features
Back end
| Source | What is searched |
|---|---|
| Posts | Title, content and excerpt of posts, pages, custom post types, menu items and reusable blocks |
| Custom fields | Post meta, including ACF, page-builder data and SEO plugin data |
| Options | Site title, tagline, widgets, Customizer settings and plugin settings (transients are skipped) |
| Comments | Comment text and author name |
| Terms | Category, tag and custom taxonomy names and descriptions |
| Theme files (optional) | Active theme and parent theme files (php, html, htm, js, css, json, txt), reported with line numbers |
Front end
The tool fetches each public URL as a logged-out visitor and searches the rendered HTML. This catches text that only exists after rendering, such as theme template text, shortcode output and plugin-generated content.
URLs scanned:
- The home page
- All published, public, non-password-protected posts, pages and custom post types
- Category, tag and other public taxonomy archives (non-empty terms)
For each page the tool reports whether the word appears in the visible text or only in the HTML source (an attribute, script, meta tag, etc.).
Search options
- Case sensitive
- Whole word only
- Back end, front end and theme files can each be toggled on or off
Results table
Each match shows the area, where it was found, the field or line, the match count, a context snippet, and View and Edit links where available.
Requirements
- WordPress 5.0+
- PHP 7.2+
- Administrator account (
manage_optionscapability)
Installation
Option 1: As a plugin
- Create the folder
wp-content/plugins/word-finder/. - Save
word-finder.phpinside it. - Activate Word Finder (Front End + Back End) under Plugins.
Option 2: As a snippet (Code Snippets, WPCode, etc.)
- Create a new PHP snippet.
- Paste the contents of
word-finder.php, excluding the opening<?phpline and the plugin header comment if your snippet plugin adds its own. - Set it to run in the admin area and activate it.
Usage
- Go to Tools → Word Finder.
- Enter a word or phrase.
- Choose where to search and any options.
- Click Search.
Back-end results appear first. Front-end pages are then fetched in batches of 5, with a progress indicator, so large sites should not time out.
Configuration (filters)
Add these to your theme's functions.php or a snippet.
| Filter | Default | Purpose |
|---|---|---|
wf_sslverify |
true |
Return false on local or dev sites with self-signed SSL certificates |
wf_max_urls |
1000 |
Maximum number of posts scanned on the front end |
wf_row_limit |
5000 |
Maximum rows read per database source |
Example:
// Local development with a self-signed certificate
add_filter( 'wf_sslverify', '__return_false' );
// Scan up to 3000 posts on the front end
add_filter( 'wf_max_urls', fn() => 3000 );
Notes and limitations
- Draft, private and password-protected content appears only in back-end results, because visitors cannot see it.
- Raw data matches: back-end matching runs on raw stored values, so a word inside a URL, an HTML attribute, a block comment or serialized data counts as a match.
- wp-admin screens are not crawled. Only their stored data is searched.
- Page caching: a
wf_scanquery parameter is added to each front-end request to help bypass page caches, but some caching layers may still serve cached copies. - Performance: the front-end scan makes one HTTP request per page. Run it during low-traffic periods on large sites.
- Case sensitivity in the database prefilter depends on your table collation. Matches are then verified in PHP, so the Case sensitive and Whole word options are applied accurately to what is displayed.
- Theme files: files larger than 1 MB and
node_modulesfolders are skipped.
Security
- Every request is protected by a nonce and requires the
manage_optionscapability. - The browser never sends URLs to fetch. The URL list is built and stored server-side (per user, 1 hour), which prevents server-side request forgery (SSRF).
- All results are inserted into the page as plain text, never as HTML.
- The tool is read-only and never modifies your content.
File structure
word-finder/
├── word-finder.php # The plugin / snippet
└── README.md # This file
License
GPL-2.0-or-later, the same license as WordPress.