
Bruce Clay SEO WP Security & Risk Analysis
wordpress.org/plugins/bruce-clay-seoNext-level SEO plugin! Get on-page guidance per keyword based on analysis of top competitors. See analytics in the WP dashboard.
Is Bruce Clay SEO WP Safe to Use in 2026?
Generally Safe
Score 85/100Bruce Clay SEO WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bruce-clay-seo' plugin v0.8.0 exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having no known vulnerabilities, several concerning aspects are present in the static analysis. The most significant weakness lies in its attack surface, with 2 AJAX handlers, both of which lack authentication checks. This opens the door to potential unauthorized actions if these handlers are exploitable. Furthermore, a very low percentage (4%) of output escaping indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities across numerous output points.
Taint analysis shows a moderate concern with 3 flows having unsanitized paths, though thankfully no critical or high severity issues were found. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the other identified risks. The plugin's history of no known vulnerabilities is a positive indicator, but it does not negate the risks identified in the current version's code. The limited total entry points are a strength, but the lack of protection on these is a significant concern. Overall, the plugin has strengths in its SQL handling and vulnerability history, but the unauthenticated AJAX actions and poor output escaping present notable risks that require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Flows with unsanitized paths
Bruce Clay SEO WP Security Vulnerabilities
Bruce Clay SEO WP Code Analysis
Output Escaping
Data Flow Analysis
Bruce Clay SEO WP Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
Bruce Clay SEO WP Maintenance & Trust
Maintenance Signals
Community Trust
Bruce Clay SEO WP Alternatives
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Semrush SEO Writing Assistant
semrush-seo-writing-assistant
The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Topic SEO Content Optimization Tool
topic
Find and fix topical gaps in your SEO Content. Rank higher on search.
Textmetrics
webtexttool
Textmetrics is the easiest way to create SEO proof content to rank higher and get more traffic. Realtime optimization, keyword research and more.
Bruce Clay SEO WP Developer Profile
1 plugin · 10 total installs
How We Detect Bruce Clay SEO WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bruce-clay-seo/css/bruce-clay-seo.css/wp-content/plugins/bruce-clay-seo/js/bruce-clay-seo.jshttps://js.recurly.com/v4/recurly.jsbruce-clay-seo/css/bruce-clay-seo.css?ver=bruce-clay-seo/js/bruce-clay-seo.js?ver=HTML / DOM Fingerprints
seotoolset