All in One SEO Pack Importer Security & Risk Analysis

wordpress.org/plugins/all-in-one-seo-pack-importer

Imports SEO data from Thesis to All in One SEO Pack. This is useful if You are leaving Thesis for a different theme or You prefer the superior SEO o …

500 active installs v.1.5.2 PHP + WP 2.1+ Updated Feb 22, 2019
all-in-one-seo-packthesis
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All in One SEO Pack Importer Safe to Use in 2026?

Generally Safe

Score 85/100

All in One SEO Pack Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "all-in-one-seo-pack-importer" plugin v.1.5.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of known CVEs in its history suggests a history of responsible development or a lack of high-profile vulnerabilities being publicly disclosed. The presence of nonce and capability checks, while minimal, is a good practice.

However, significant concerns arise from the code analysis. A notable weakness is the complete lack of prepared statements for all nine SQL queries. This is a substantial risk, as it exposes the plugin to potential SQL injection vulnerabilities. Additionally, none of the seven output operations are properly escaped, meaning there's a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of taint analysis data is also a gap, as it prevents a deeper understanding of potential data handling risks. While the plugin has no known vulnerabilities currently, the identified coding practices (raw SQL and unescaped output) present inherent risks that could be exploited if an attacker finds a suitable entry point.

In conclusion, while the plugin has a small attack surface and a clean vulnerability history, the critical coding flaws related to SQL queries and output escaping present significant, exploitable risks. Developers must address these issues to improve the plugin's security.

Key Concerns

  • All SQL queries use prepared statements
  • No output is properly escaped
Vulnerabilities
None known

All in One SEO Pack Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All in One SEO Pack Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared9 total queries

Output Escaping

0% escaped7 total outputs
Attack Surface

All in One SEO Pack Importer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuall-in-one-seo-pack-importer.php:12
Maintenance & Trust

All in One SEO Pack Importer Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedFeb 22, 2019
PHP min version
Downloads139K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

All in One SEO Pack Importer Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect All in One SEO Pack Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
name="migrate-aioseopi"value="<?php echo wp_create_nonce( 'aioseopi-migrate-nonce' ); ?>"
Shortcode Output
<input type="submit" class="button-primary" value="Import Thesis SEO Data"/>
FAQ

Frequently Asked Questions about All in One SEO Pack Importer