The FindWeave user guide – bundled with the plugin, readable without an internet connection.
Getting started
Getting started with FindWeave
Installation, menu, rights and the first search in a few minutes.
Where in WordPress: WordPress → Plugins → FindWeave; then the FindWeave menu
What FindWeave does
FindWeave answers a simple question: where is this text stored? It searches the stored titles, contents and custom fields of your posts and pages, selected site settings and widgets, and the files of selected plugins and themes. Every match names its proven source and the matching editing path. Those who may do so prepare a change from it, check it in a preview and execute it as a confirmed plan – with a journal and rollback.
Installation
Upload the plugin package (Plugins → Add New → Upload Plugin) or install it from the plugin directory.
Activate FindWeave. On activation the plugin creates its own tables and grants administrators every FindWeave right.
Open the new FindWeave menu in the left sidebar. The entry appears only for users with the right findweave_search_content.
The FindWeave screen with header and search panel
The screen at a glance
The menu selects one tool area at a time: Search, Replace one image, Change plans, Export and import, or Search runs. Only permitted areas appear. Search includes matches, source locations and replacement previews. Change plans shows the list first and the selected plan below it. Opening a saved search or creating a plan automatically switches to the matching area without losing your entered values.
The current menu item is white on teal. On narrow screens the menu wraps onto additional rows without sideways scrolling. Notices appear above the logo and heading. Use Tab, arrow keys, Home and End; Enter selects a focused entry. The URL remembers the area and browser Back restores the previous area. Without JavaScript the sections remain readable in order.
The first search
Enter a term in Search text, for example a phone number or a company name. 2 to 200 UTF-8 bytes are allowed; the search is literal and case-sensitive.
Leave Search in: Posts and pages and the fields Title and Content selected.
Click Find text. Large areas are checked in steps; the status line shows the progress and you can cancel at any time.
The matches appear as a table with source and editor link.
Where to read on
The chapter Searching explains areas, fields and regular expressions. Understanding matches explains the source details. Rights and roles shows which rights you can give to other roles.
Upgrade information
Administrators can open a local price and feature overview from the header and FindWeave → Upgrade. The cards show 1 website, 5 websites and unlimited websites for €39, €79 and €149 per year, including 19% German VAT. Billing is annual with automatic renewal. Taxes are adjusted to your billing country at checkout. Expandable questions explain features, updates, cancellation and subscription expiry. Go to checkout opens the external checkout in euros for the selected website count in a new tab only after your click. The free search and all other existing tools remain available independently. Other search users do not see this administrative action.
What FindWeave searches, what it deliberately leaves out and how regular expressions work.
Where in WordPress: FindWeave → Where is this text?
Search text
The search text is literal: FindWeave looks for exactly the entered characters and distinguishes upper and lower case. 2 to 200 UTF-8 bytes without control characters are allowed. Patterns use the search mode Regular expression.
Search areas, content types, fields and search mode
Search in: Posts and pages
The stored raw texts of the current site are searched: published, draft, pending, private and scheduled posts and pages you may read and edit. Password-protected posts, revisions, the trash and other content types stay out. Blocks and shortcodes are not executed; the stored text is shown.
Content types: posts, pages or both.
Fields: title, content and custom fields. For custom fields only non-protected fields (no leading underscore) of the matched posts are read, at most 500 fields per object and 256 KiB per value. Serialized strings and arrays are read without execution and shown with their path; values with objects or an unknown structure are searched as raw text only and marked accordingly.
Search in: Settings and widgets
Only a fixed list of harmless core settings is read, each with its responsible settings screen: title and tagline, WordPress and site address, administration email, timezone, date and time format, language, permalink structure, category and tag base, block, text and custom HTML widgets and the theme modifications of the active theme. All other options – in particular plugin configurations, keys, credentials, transients, cron and roles – are never read. This area appears only when you hold the related rights (manage options, edit theme options).
Search in: Plugin and theme files
Under Plugins and themes choose the folders to search. Text files (PHP, JavaScript, CSS, HTML, Twig, text, Markdown, JSON, XML, SVG, translations) up to 1 MiB are read line by line and read-only. Never read are hidden files and folders, vendor, node_modules, cache, log, backup and temp folders, names that hint at credentials, configuration or backups, files containing a private key, binary files and symbolic links. Must-use plugins, drop-ins, uploads and WordPress core are not search areas. Skipped or faulty files are logged and make the result “incomplete”.
Search mode: Regular expression
A PCRE pattern without delimiters and modifiers, always UTF-8. (?i) at the start ignores case. Control verbs such as (*…) and callouts are blocked; backtracking and recursion are limited. If a pattern hits this limit, the source is logged and the search continues. An invalid pattern is explained without starting a search run.
Limits per search run
Limit
Value
Objects or files per step
200
Data per step
8 MiB, at most 2 seconds
Skipped
objects above 256 KiB
Objects per search run
10,000
Data volume per search run
256 MiB
Matches per search run
100
When a limit is reached, the search run ends as incomplete and names the reason in the status.
Additional theme and plugin content (since 1.1.0)
Website contents includes public editorial content types registered by installed themes and plugins. Saved templates, template parts, navigation and reusable blocks require the corresponding WordPress permissions. Private internal types stay excluded. Searches remain limited to the current site and the documented size and time budgets.
Readable HTML and block text finds phrases interrupted by markup or JSON escapes in stored content. It reads HTML fragments and individual string attributes without rendering blocks or executing shortcodes. Attributes may contain technical text; a match proves storage, not actual front-end use. Saved block documents, raw block contents, additional metadata adapters and readable-text matches remain read-only. Simple title, content and excerpt fields of public editorial types use native WordPress writers through a confirmed plan. Content export continues to cover posts, pages, their allowed custom fields and selected settings.
Use Settings and widgets for saved Customizer values, or Plugin and theme files for PHP, JavaScript and template source. File search matches stored source literally: use a distinctive fragment when formatting or concatenation interrupts a sentence. Computed text, runtime translations, external services, third-party tables and arbitrary plugin settings are not a complete rendered-site search.
Excerpts, comments, categories and tags
In Website contents, select Excerpt to search the stored post excerpt. Comments searches only the text of approved or pending ordinary comments whose parent content you may read and edit. Moderation and comment-editing rights are also required. Spam, trash, pingbacks and comments on password-protected content are excluded; author names, email/IP addresses and comment metadata are not search fields.
Categories and tags searches names and descriptions of the two WordPress core taxonomies. Custom taxonomies are excluded. Each term requires its current editing permission. Results identify the object and field and link to the responsible WordPress editor. These native text fields support preview, confirmed plans and conflict-checked rollback. Export remains limited to its documented original sources.
Both areas use the same per-step and per-run limits above. A term can have one result in its name and another in its description. Recognized credentials are withheld, and saved results are checked again when opened: missing or inaccessible sources disappear and changed values are marked.
Content filters and text options
Under Website contents, open Content filters and text options. Limit the search by post status, author IDs, publication date, and category or tag IDs. Find an object ID in its WordPress edit URL. Leave optional ID fields empty or enter up to 50 distinct positive IDs separated by commas. Any ID within one field may match; all filter kinds must match. Categories apply to direct assignments, without descendants. Both dates include the entire day in the site timezone. An empty status selection or an invalid date range is rejected.
Match case is enabled by default. Disable it to use the same Unicode case matching and original byte positions in search, preview and replacement. Literal searches still treat pattern characters as text. Explicit regex inline options such as (?i) may override the default flag.
Filters are fixed in the stored search run and shown with results and history. If a saved source no longer matches its filters, the result is withheld. Current filters are also checked before confirmed changes or rollback; values outside the scope are not overwritten. Older runs without filters remain readable. Fixed search budgets also count examined candidates outside the filters. These filters currently apply to Website contents only.
Editorial changes
Native title, content and excerpt fields of public editorial types, comment text and category/tag fields can be changed through preview and confirmed plans and rolled back with conflict checks. Saved block documents, raw block contents, normalized-text findings and additional metadata adapters remain read-only. Use their responsible editor. Old jobs with read-only findings stay read-only; start a new search to use the new writers.
What the table shows, what “source” means and where the links lead.
Where in WordPress: FindWeave → Matches
The table
Every row is a match in one field or one line. The column Match shows the stored raw text around the first occurrence; HTML is shown as text and never executed. The column Source names the proven storage location: site, post or page with its id, the field and, for custom fields, the path inside a serialized value.
Matches with source and editor link
What “source” means
FindWeave proves the storage location, not the usage: it says in which field of which row the text is stored. Whether and where that text appears on the public site is decided by the theme, blocks and plugins – that stays unknown and is not claimed. A value with an unknown structure is marked as such and treated as raw text only.
Editing paths
Open in editor leads to the WordPress editor of the post or page.
Open settings leads to the responsible settings screen; widgets and theme modifications to their own administration.
Show source location opens a permitted file at the matched line in read-only mode. Protected files stay excluded.
Status and completeness
The status line above the table names the number of matches and of checked objects and whether the search run was complete. Incomplete means: sources were skipped, limits were reached or the run was cancelled. The reason is stated; skipped files and hidden entries sit in the collapsible log below the table.
Paging
From 100 matches on, the table shows pages of 25 or 50 rows with a bar above and below. The chosen page size is kept for the search run, also after reloading.
Matches as CSV
After completing or stopping a search, users with export permission can choose Export matches as CSV, then Download CSV. The UTF-8 file contains currently accessible findings with title, source, field, excerpt, job status and source state. Stale findings remain marked; export does not repeat the search. Lost permissions hide findings during export too. Spreadsheet formulas are neutralized with a leading apostrophe. The file is offered in the browser only and is not a backup.
Why a search runs in steps and how you show stored search runs again.
Where in WordPress: FindWeave → Your recent search runs
Steps instead of one long request
Large sites cannot be searched in a single request. FindWeave therefore checks in steps of at most 200 objects, 8 MiB and 2 seconds and continues automatically until the search area is exhausted or a limit applies. While running, the status line shows the progress and the button Cancel search run.
Cancelling
A cancellation stops the run at once. Matches found so far stay visible; the run counts as cancelled and incomplete. A late answer of a step still running cannot overwrite the cancellation.
List of recent search runs with show and delete
Stored search runs
Your recent search runs lists up to five search runs of the last 60 minutes – only your own and only for sources you may currently read. You can show them again, continue or delete them. A search run stores the search text, progress, matches and the log of skipped files in the plugin’s own table of this site.
Retention
Search runs are deleted automatically 60 minutes after they started; at most the five newest are kept per user. You can delete a search run yourself at any time.
Enter the replacement text, check before and after, change nothing.
Where in WordPress: FindWeave → Prepare a change
When the panel appears
The panel Prepare a change appears after a finished search run in posts, pages, custom fields or settings when you hold the right findweave_plan_changes. File matches open in a read-only source view.
Replacement text
Enter the new text (0 to 200 UTF-8 bytes). It is inserted literally by default, even for a search run with a regular expression. An empty replacement removes the search text.
Preview with before and after per value
Calculate preview
Calculate preview re-reads every matched value now and shows before and after side by side. Nothing is written. Serialized arrays are rewritten without execution, with corrected lengths. Values with objects or an unknown structure stay locked and are not changed. The status line names how many values are ready and how many are locked.
From proposal to plan
Create a plan from this preview freezes the preview into a change plan. Only that plan writes – after your confirmation. The chapter Change plan explains how.
Native editorial fields
Excerpts, simple title/content fields of public editorial types, comments and category/tag names/descriptions use the same preview and confirmation. These fields are plain strings, even when their text resembles serialized data. WordPress may sanitize or filter a write; FindWeave verifies the actual stored value and reports differences in the journal. Raw block documents stay read-only.
Capture groups (optional)
For a regex search, explicitly choose Capture groups: $0 means the whole match, $1 to $99 or ${1} refer to numbered groups. Example: search (Hello) (world), replace with $2 – $1 to obtain world – Hello. $$ inserts a dollar sign; backslashes remain literal. Unmatched optional groups yield empty text; nonexistent group numbers are an error. The mode is frozen in the preview and confirmed plan. Old plans remain literal. Rollback restores the exact original bytes. Patterns whose groups cannot be safely determined and oversized results stay blocked.
Select values
Use the checkboxes in the preview table to choose which stored values enter the plan. Ready values start selected; uncheck values you want to keep. Selection survives pagination. An empty selection cannot create a plan. All matching text within a selected value is replaced, not individual offsets. The plan freezes the selected values and their before/after bytes. If selected sources become unavailable, refresh the preview.
Widget and settings safeguards
FindWeave accepts only values that the matching WordPress safeguards allow unchanged. A change is locked if, for example, disallowed HTML would have to be removed. This also applies to imports and rollback; a previously valid plan may be blocked after permissions change. Theme modifications remain searchable. Edit them through the displayed WordPress editing link so the theme’s own checks apply.
Every value is written exactly once, only if it still equals the before value – with journal and rollback.
Where in WordPress: FindWeave → Change plan and Your change plans
Draft
A new plan is a draft. It lists every value with source, before and after and a checksum of the whole plan. Drafts expire after 30 minutes. Plans hold at most 200 items.
Executed change plan with the result per value
Confirm and execute
Confirm and execute needs the right findweave_execute_changes. Before every write FindWeave checks again whether the value still equals the before value exactly. Only then it writes, every value exactly once. If a value changed in the meantime, it stays as a conflict and is not overwritten. The result per value – written, conflict, skipped – is shown in the table; the plan counts as completely or partially executed.
Journal
Before and after values are recorded in the journal of this site. Executed plans are kept with their journal for seven days and can be deleted earlier; deleting removes the rollback of that plan.
Rollback
Prepare rollback creates a counter plan with before and after swapped. It is confirmed and executed like any plan and writes a value back only if it is still stored exactly as FindWeave wrote it. A later change by someone else stays untouched.
Your change plans
The list shows your plans of this site with their state: draft, confirmed, completely or partially executed, cancelled. Show opens the plan in the change plan panel; Delete removes it together with its journal.
WP-CLI in the terminal
wp help findweave lists the core commands: search, status, continue, preview, plan, confirm, execute, rollback, jobs, plans, roots, csv. Every call requires --user, --url and the matching --site-id. The user needs the same permissions as in the UI. Pass search/replacement input as JSON through --data. Output is JSON with ok and data, errors with error.code. Before writing, read the complete plan through status ID --kind=plan, then confirm its exact plan_hash with confirm ID --hash=…. Use execute ID --step=… with the current step. Rollback also creates a separate draft requiring explicit confirmation. No automatic approval, including for operating-system root. Exit codes: 0 successful call (check plan status), 2 input/conflict, 3 permission/context, 4 not found, 1 other failure.
Media texts and replacing one image
Choose Media texts to find and change titles, descriptions, captions and alternative text of editable attachments. Media and parent-post permissions are checked again before changes. No arbitrary protected metadata is exposed.
Under Replace one image, choose an existing image and upload its replacement. Preview image replacement shows both images without changing the attachment. Create the plan, inspect it, then confirm and execute. Attachment ID, original URL and existing thumbnail filenames stay unchanged. WordPress generates the image sizes. A smaller replacement can produce smaller dimensions at an existing thumbnail URL.
Supported: local, static JPEG, PNG and WebP in the same format; at most 1 MiB per file, 4 million pixels, 12 registered/existing sizes and 4 MiB per full file snapshot. SVG, GIF, animated images, offloaded files, shared paths, symlinks, Core original/edit backups and unknown metadata layouts are excluded. EXIF orientation is applied; re-encoding may remove ancillary metadata. CDN/browser caches may retain an old image until refreshed.
The journal stores exact before/after image bytes and attachment metadata privately in this site's database for the plan retention period. Prepare rollback restores these bytes and metadata and removes only newly generated sizes. Deleting the plan removes this recovery option. Read-only files or changed images stop execution. A known partial write can be rolled back explicitly; unknown later changes remain untouched.
The Change plans area lists your plans above the detail. Show opens and focuses the selected detail below the list.
Open the verified storage location of a file match without changing it.
Where in WordPress: FindWeave → Search results
Open a match
Click Show source location in a file result. FindWeave shows the theme or plugin, relative file path and line number. A bounded context surrounds the highlighted line. Copy path copies the complete server path shown above the source code, including the plugin or theme folder. This is a filesystem location for your host or SFTP, not a public URL. Back to search results restores focus and the previous scroll position; the result page stays selected.
Current and permitted sources
The viewer rechecks the owner of the search, current site and file permissions, exclusion rules and file fingerprint. If a file changed, disappeared or became protected, run a new search. Expired searches cannot open a location. Long lines are truncated and only a small context is shown. Contents are displayed as text, never executed. File editing is not available, and old file-change plans cannot be executed or rolled back. Their journal remains under the normal retention policy.
Storage location and public page
A file can be used on multiple pages or not at all. FindWeave does not guess a public URL from a template name. Supported stored WordPress content links to its responsible editor; the exact word or field may still need to be found inside that editor. Search and confirmed changes to supported editorial content remain available.
For stored WordPress content, Copy path copies the verified link to the responsible editor. It does not promise a jump to an individual word inside that editor.
Save content as a data file, rewrite domains and prefixes, import into test installations.
Where in WordPress: FindWeave → Export, migration and import
Export
Create export (right findweave_export_content) writes only the sources FindWeave also searches and changes: posts and pages (id, title, content), their custom fields and the allowed settings and widgets. The format is an own, strictly limited data format with checksum and site binding. Credentials, users, sessions, foreign plugin configurations and all other tables are never included. The export is not a database backup and replaces none. The file is transferred to your browser only and not stored on the server; at most 2,000 posts and 8 MiB.
The panel Export, migration and import
Domain and prefix tool
The tool works on an export file only: it rewrites one domain into another – also within serialized values with corrected lengths – and optionally renames the table prefix. GUIDs stay unchanged by default. The result is downloaded; nothing on this site changes.
Import into this site
The import (right findweave_import_content) is meant for test installations. It reads an export file as data, verifies checksum, table prefix and site binding and compares every value with the current state. Calculate preview shows what would change. Changes happen only through a confirmed plan with journal and rollback – like every other change in FindWeave.
Six own rights control who may search, plan, execute and export.
Where in WordPress: WordPress roles (through a role plugin) → rights with the prefix findweave_
The rights
Right
Allows
findweave_search_content
Seeing the FindWeave menu and searching posts, pages and custom fields
findweave_read_files
Searching plugin and theme files
findweave_plan_changes
Calculating previews and creating change plans
findweave_execute_changes
Executing and rolling back confirmed plans
findweave_export_content
Creating exports and using the domain and prefix tool
findweave_import_content
Importing export files into this site
Who receives them
On activation administrators receive all seven rights. Other roles receive nothing automatically; you grant rights deliberately, for example with a role plugin. An editor with findweave_search_content can search but neither plan nor execute.
Object rights on top
Rights unlock panels; the view of single values is checked per object as well: FindWeave shows only posts and pages you may read and edit, only settings whose settings screen is open to you, and writes only values you could also change in the WordPress editor. Search runs and plans belong to their owner and are bound to the current site.
Multisite
Activate FindWeave per site. Network activation is refused; tables, options and rights always apply to the current site.
Multisite: one subsite per operation
Activate FindWeave individually on each required subsite. New subsites are not activated automatically. Network activation and central network jobs are unavailable here. Searches, change plans and journals use the selected subsite’s own tables. Users need explicit membership and the relevant role/object permissions there, including network administrators. The CLI requires the matching URL and site ID.
Deactivation stops open work only on that subsite and keeps history. Complete uninstallation removes the plugin from the installation: FindWeave then removes its tables, schema marker and role/direct-user permissions on every existing subsite. Content, unrelated options and unrelated permissions remain. Use any needed journal before uninstalling; rollback is unavailable after its deletion.
Custom post fields are shown and changed only when WordPress permits editing that specific field. Revoked field permissions also apply to saved results, exports, plans and rollback. History is retained, but restricted values are withheld.
Which data FindWeave stores, what it never sends and how everything disappears again.
Where in WordPress: WordPress → Plugins → FindWeave → Deactivate / Delete
Own data
FindWeave stores only its working data in its own tables of this site: search runs (search text, progress, matches, log; 60 minutes) and change plans with journal (before and after values of the changed content; seven days after completion). Because content can contain personal data, the same care applies to the journal and to export files as to the content itself.
Distribution and external services
FindWeave Free includes no distribution SDK and needs no account or licence. Its tools do not contact the checkout provider automatically. FindWeave does not send search text, matches, journals or export files to that provider. Export files go to your browser.
The existing purchase links open the external checkout only after you click. Its privacy policy and terms apply there.
Deleting
All own data can be deleted on the FindWeave screen at any time: search runs under Your recent search runs, plans with their journal under Your change plans. Deactivation stops running search runs and open plans. Uninstalling removes the three owned working tables, the schema option and assigned FindWeave capabilities. Content remains unchanged; data belonging to other plugins is not removed.
Protection limits
Known credential and configuration keys are excluded, including credentials in structured values. Plan excerpts are withheld when access to their source is lost. Arbitrary content may still contain personal or sensitive data; exclusions do not replace reviewing data before sharing it.
Where in WordPress: FindWeave → status lines of the panels
“Incomplete”
A search run ends incomplete when sources were skipped, a limit was reached or you cancelled. The status names the reason: match limit reached, object limit or data volume of the search run reached, skipped files. Narrow the area or search more precisely; skipped files are listed in the log below the table.
“No matches to show”
The text is stored in no searched field you may read. Check upper and lower case, the chosen area and the fields; custom fields must be ticked explicitly.
“Invalid regular expression”
The pattern is not a valid PCRE pattern or uses blocked parts. Write it without delimiters and modifiers; (?i) ignores case.
A panel is missing
Panels appear only with the matching right: files with findweave_read_files, preview and plan with findweave_plan_changes, executing with findweave_execute_changes, export and import with the export and import rights. See Rights and roles.
“Preview not possible”
The replacement text contains control characters or is too long (at most 200 UTF-8 bytes). Tabs and line breaks are not allowed.
Conflicts in the plan
A value was changed by someone else between preview and execution. FindWeave does not overwrite it. Search again and create a new plan.
Draft expired
Drafts expire 30 minutes after they were created. Calculate the preview again and create the plan anew.
Source location unavailable
The file changed, is no longer readable or the search expired. Run a new search. No file is written.
Getting help
This handbook ships with the plugin under FindWeave → Handbook and can be read without an internet connection. For questions use the contact option of the publisher delivered with the plugin.