WPGraphQL Yoast SEO Addon Security & Risk Analysis

wordpress.org/plugins/add-wpgraphql-seo

This plugin enables Yoast SEO Support for WPGraphQL.

9K active installs vv5.0.2 PHP 7.1+ WP 5.0+ Updated Feb 4, 2026
graphqlheadless-wordpressseowpgraphqlyoast
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPGraphQL Yoast SEO Addon Safe to Use in 2026?

Generally Safe

Score 100/100

WPGraphQL Yoast SEO Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of add-wpgraphql-seo version 5.0.2 reveals an exceptionally clean codebase with no identified attack surface, dangerous functions, file operations, external requests, or issues with SQL queries, output escaping, nonces, or capability checks. Taint analysis also shows no problematic data flows. The plugin's vulnerability history is equally spotless, with no recorded CVEs of any severity. This indicates a strong adherence to secure coding practices and a mature development process.

While the absence of any identified vulnerabilities or weaknesses is highly positive, it's important to note that a completely clean bill of health in static analysis doesn't guarantee absolute security. The lack of capability checks, while not a direct vulnerability in this context due to zero attack surface, could be a point of concern if the plugin were to evolve and introduce new entry points without robust authorization mechanisms. However, based on the current data, the overall security posture is excellent, with no immediate risks identified for this version.

Vulnerabilities
None known

WPGraphQL Yoast SEO Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPGraphQL Yoast SEO Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped15 total outputs
Attack Surface

WPGraphQL Yoast SEO Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_initincludes\admin\dependencies.php:15
actionnetwork_admin_noticesincludes\admin\dependencies.php:40
actionadmin_noticesincludes\admin\dependencies.php:41
actiongraphql_register_typesincludes\resolvers\post-type.php:96
actiongraphql_register_typesincludes\resolvers\root-query.php:17
actiongraphql_register_typesincludes\resolvers\taxonomy.php:17
actiongraphql_register_typesincludes\resolvers\user.php:17
actiongraphql_register_typesincludes\schema\types.php:12
actiongraphql_initwp-graphql-yoast-seo.php:37
Maintenance & Trust

WPGraphQL Yoast SEO Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.1
Downloads160K

Community Trust

Rating100/100
Number of ratings2
Active installs9K
Developer Profile

WPGraphQL Yoast SEO Addon Developer Profile

ash_hitch

3 plugins · 10K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPGraphQL Yoast SEO Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-wpgraphql-seo/admin/css/styles.css/wp-content/plugins/add-wpgraphql-seo/admin/js/scripts.js
Script Paths
/wp-content/plugins/add-wpgraphql-seo/admin/js/scripts.js
Version Parameters
add-wpgraphql-seo/admin/css/styles.css?ver=add-wpgraphql-seo/admin/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-graphql-yoast-seo-admin-page
FAQ

Frequently Asked Questions about WPGraphQL Yoast SEO Addon