
Auto Focus Keyword for SEO Security & Risk Analysis
wordpress.org/plugins/auto-focus-keyword-for-seoAutomatically fill missing Yoast SEO or Rank Math focus keywords from post titles. Batch sync, exclusions, and Pro auto-sync.
Is Auto Focus Keyword for SEO Safe to Use in 2026?
Generally Safe
Score 100/100Auto Focus Keyword for SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'auto-focus-keyword-for-seo' v1.0.4 plugin exhibits a mixed security posture. On the positive side, the plugin utilizes prepared statements for all its SQL queries, a crucial practice to prevent SQL injection. It also demonstrates a good number of nonce and capability checks, indicating some awareness of WordPress security best practices. Furthermore, the absence of known CVEs and no recorded vulnerabilities in its history suggest a relatively stable past. The taint analysis also shows no critical or high-severity flows with unsanitized paths, which is a strong indicator of secure data handling within the analyzed flows.
However, significant security concerns arise from the plugin's attack surface. With a total of 4 AJAX handlers, all 4 are completely unprotected and lack any form of authentication or authorization checks. This creates a substantial entry point for potential attackers to interact with the plugin's backend logic without proper validation. Additionally, while there are nonce and capability checks present, the fact that they are not applied to all identified AJAX handlers is a critical oversight. The output escaping also appears to be a weakness, with only 32% of outputs being properly escaped, leaving room for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed.
In conclusion, while the plugin has a clean vulnerability history and employs good practices in its database interactions, the significant number of unprotected AJAX endpoints and the subpar output escaping present immediate and serious risks. These weaknesses could be exploited to gain unauthorized access or execute malicious scripts within the WordPress environment.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Bundled outdated library (Freemius v1.0)
Auto Focus Keyword for SEO Security Vulnerabilities
Auto Focus Keyword for SEO Release Timeline
Auto Focus Keyword for SEO Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Auto Focus Keyword for SEO Attack Surface
AJAX Handlers 4
WordPress Hooks 10
Maintenance & Trust
Auto Focus Keyword for SEO Maintenance & Trust
Maintenance Signals
Community Trust
Auto Focus Keyword for SEO Alternatives
Yoast Test Helper
yoast-test-helper
This plugin makes testing Yoast SEO, Yoast SEO add-ons and integrations and resetting the different features a lot easier.
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
WP SEO HTML Sitemap
wp-seo-html-sitemap
A responsive HTML sitemap that uses all of the settings for your XML sitemap in the WordPress SEO by Yoast Plugin.
Turn Rank Math FAQ Block to Accordion
turn-rank-math-faq-block-to-accordion
This plugin turns Rank Math FAQ blocks into accordion easily and make them accessibility ready.
Turn Yoast SEO FAQ Block to Accordion
faq-schema-block-to-accordion
This plugin turns Yoast SEO FAQ block into accordion easily.
Auto Focus Keyword for SEO Developer Profile
17 plugins · 33K total installs
How We Detect Auto Focus Keyword for SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-focus-keyword-for-seo/admin/assets/css/settings.css/wp-content/plugins/auto-focus-keyword-for-seo/admin/assets/js/settings.js/wp-content/plugins/auto-focus-keyword-for-seo/admin/assets/js/settings.jsauto-focus-keyword-for-seo/admin/assets/css/settings.css?ver=auto-focus-keyword-for-seo/admin/assets/js/settings.js?ver=HTML / DOM Fingerprints
afkw-settings-pagedata-nonceafkw_settings/wp-json/afkw/v1/bulk_fetch