Canonical SEO Security & Risk Analysis

wordpress.org/plugins/canonical-seo

Plugin adds posibility to edit canonical URL and meta description

1K active installs v1.0.0 PHP 7.4+ WP 4.7+ Updated Feb 11, 2025
canonicalmeta_descriptionseo
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Canonical SEO Safe to Use in 2026?

Generally Safe

Score 92/100

Canonical SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The canonical-SEO v1.0.0 plugin exhibits a strong security posture based on the provided static analysis results. The absence of any identified attack surface entries, dangerous functions, raw SQL queries, or unescaped output indicates robust development practices. Furthermore, the presence of nonce and capability checks, coupled with 100% prepared statements for SQL and proper output escaping, suggests a mature approach to security. The plugin's vulnerability history is also clean, with zero recorded CVEs, reinforcing its current stability. However, the analysis of zero taint flows means that the potential for complex injection vulnerabilities, while not detected, cannot be definitively ruled out without more extensive analysis. The plugin demonstrates excellent foundational security, but the lack of taint analysis leaves a small, theoretical window for potential, yet undetected, vulnerabilities.

Vulnerabilities
None known

Canonical SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Canonical SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Canonical SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadd_meta_boxesinclude\canonical-seo-class.php:24
actionsave_postinclude\canonical-seo-class.php:25
actionwp_headinclude\canonical-seo-class.php:28
filterget_canonical_urlinclude\canonical-seo-class.php:31
actionplugin_loadedinclude\canonical-seo-class.php:221
Maintenance & Trust

Canonical SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 11, 2025
PHP min version7.4
Downloads843

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Canonical SEO Developer Profile

Toma

1 plugin · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Canonical SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
cseo_canonical_urlcseo_meta_descriptioncseo_meta_box_nonce
FAQ

Frequently Asked Questions about Canonical SEO