SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Security & Risk Analysis

wordpress.org/plugins/ai-for-seo

Lightweight SEO Autopilot that works with Yoast SEO, Rank Math, SEOPress, WooCommerce etc. to bulk-generate keyphrases, meta tags, alt text and more.

2K active installs v2.3.0 PHP 7.4+ WP 4.7+ Updated Mar 9, 2026
aialt-textbulkgoogle-search-consoleseo
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Safe to Use in 2026?

Generally Safe

Score 99/100

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2025Updated 25d ago
Risk Assessment

The 'ai-for-seo' v2.3.0 plugin exhibits a generally positive security posture with some areas of concern. The static analysis indicates a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, the code does not utilize dangerous functions, perform file operations, or make external HTTP requests, which are all good security practices. The high percentage of properly escaped output and the presence of nonce checks are also encouraging signs.

However, several aspects warrant attention. The taint analysis reveals two flows with unsanitized paths, although thankfully none were flagged as critical or high severity. The SQL query usage is mixed, with 50% not using prepared statements, which could present a risk if these queries are exposed to untrusted input. The complete absence of capability checks on any entry points, combined with no apparent authorization checks on the AJAX handlers and REST API routes (though there are none reported), suggests a potential gap in enforcing user roles and permissions. The vulnerability history, while showing no currently unpatched CVEs, indicates a past medium severity vulnerability related to missing authorization. This pattern, alongside the lack of capability checks, points to a recurring area of risk.

In conclusion, 'ai-for-seo' v2.3.0 has strong defenses in place regarding its attack surface and output sanitization. Nevertheless, the presence of unsanitized paths in taint flows, the reliance on non-prepared SQL queries, and the historical and current lack of explicit capability checks represent vulnerabilities that should be addressed to further strengthen the plugin's security.

Key Concerns

  • Unsanitized paths in taint flows
  • SQL queries not using prepared statements
  • No capability checks
  • Past medium severity vulnerability (missing authorization)
Vulnerabilities
1

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22299medium · 5.3Missing Authorization

AI for SEO <= 1.2.9 - Missing Authorization

Jan 6, 2025 Patched in 1.2.10 (10d)
Code Analysis
Analyzed Mar 16, 2026

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
334
671 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

67% escaped1005 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<attachment-attributes-editor> (includes\ajax\display\attachment-attributes-editor.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads43K

Community Trust

Rating100/100
Number of ratings10
Active installs2K
Developer Profile

SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot) Developer Profile

Space Codes

2 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-for-seo/assets/css/ai-for-seo.css/wp-content/plugins/ai-for-seo/assets/css/ai-for-seo-lite.css/wp-content/plugins/ai-for-seo/assets/js/ai-for-seo-lite.js/wp-content/plugins/ai-for-seo/assets/js/ai-for-seo.js
Script Paths
/wp-content/plugins/ai-for-seo/assets/js/ai-for-seo-lite.js/wp-content/plugins/ai-for-seo/assets/js/ai-for-seo.js
Version Parameters
ai-for-seo/assets/css/ai-for-seo.css?ver=ai-for-seo/assets/css/ai-for-seo-lite.css?ver=ai-for-seo/assets/js/ai-for-seo-lite.js?ver=ai-for-seo/assets/js/ai-for-seo.js?ver=

HTML / DOM Fingerprints

CSS Classes
ai4seo-modal-headlineai4seo-modal-headline-iconai4seo-modal-sub-headlineai4seo-attachment-editor-image-previewai4seo-generate-all-attachment-attributes-button-hookai4seo-clear-bothai4seo-formai4seo-editor-form+3 more
HTML Comments
<!-- Displays the metadata editor. Called via AJAX. --><!-- === PREPARE =============================================================================== --><!-- === CHECK PARAMETER ============================================== --><!-- === GET ADDITIONAL DETAILS ===================================================================== -->+10 more
Data Attributes
data-ai4seo-attachment-post-iddata-ai4seo-attachment-attributes
JS Globals
ai4seo_send_ajax_errorai4seo_allowed_image_mime_typesAI4SEO_ATTACHMENT_ATTRIBUTES_DETAILSai4seo_can_manage_this_pluginai4seo_this_attachment_post_idai4seo_all_attachment_post_ids+14 more
REST Endpoints
/wp-json/ai-for-seo/v1/attachment-attributes/get
FAQ

Frequently Asked Questions about SOOZ – AI for SEO – Bulk Generate Focus Keyphrases, Metadata, Alt Text (SEO Autopilot)