Consolety – SEO plugin for Traffic, Authority & Backlinks Security & Risk Analysis

wordpress.org/plugins/consolety

This plugin is part of consolety.net project. Plugin let users exchange with backlinks between their sites, connect their social medias and much more.

50 active installs v4.0.2 PHP 7.2+ WP 5.0+ Updated Sep 17, 2021
backlinkslink-buildinglink-exchangelink-partnerseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Consolety – SEO plugin for Traffic, Authority & Backlinks Safe to Use in 2026?

Generally Safe

Score 85/100

Consolety – SEO plugin for Traffic, Authority & Backlinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The consolety v4.0.2 plugin exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a potentially well-maintained codebase, the static analysis reveals significant concerns regarding its attack surface. A high number of AJAX handlers (8 total) are present, with a concerning majority (7 out of 8) lacking proper authentication checks. This creates a substantial entry point for attackers to interact with plugin functionality without authorization.

The code analysis also flags the use of the `unserialize` function, which can be dangerous if used with untrusted input, potentially leading to code execution vulnerabilities. While the taint analysis did not reveal any exploitable flows, the presence of `unserialize` without clear sanitization strategies on the input it processes remains a potential risk. The low percentage of properly escaped output further exacerbates this, suggesting that even if data is not directly manipulated, it could be displayed in a harmful manner.

In conclusion, the plugin's lack of historical vulnerabilities is a positive sign. However, the static analysis highlights critical weaknesses in its attack surface management and secure coding practices, particularly concerning unauthenticated AJAX endpoints and the use of `unserialize` with potentially unsanitized data. These factors significantly increase the risk of exploitation, despite the absence of known vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • Use of unserialize function
  • Low output escaping percentage
  • Low nonce check coverage
Vulnerabilities
None known

Consolety – SEO plugin for Traffic, Authority & Backlinks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Consolety – SEO plugin for Traffic, Authority & Backlinks Code Analysis

Dangerous Functions
1
Raw SQL Queries
4
9 prepared
Unescaped Output
57
12 escaped
Nonce Checks
2
Capability Checks
7
File Operations
0
External Requests
8
Bundled Libraries
0

Dangerous Functions Found

unserialize$site = unserialize($obj);classes\Entity\Site.php:33

SQL Query Safety

69% prepared13 total queries

Output Escaping

17% escaped69 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_categories (classes\Ajax.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Consolety – SEO plugin for Traffic, Authority & Backlinks Attack Surface

Entry Points8
Unprotected7

AJAX Handlers 8

authwp_ajax_flush_consoletyclasses\Ajax.php:18
authwp_ajax_consolety_reportclasses\Ajax.php:19
authwp_ajax_consolety_exportclasses\Ajax.php:20
authwp_ajax_consolety_export_singleclasses\Ajax.php:21
authwp_ajax_save_categoriesclasses\Ajax.php:22
noprivwp_ajax_consolety_reportclasses\Ajax.php:23
authwp_ajax_consolety_click_recordclasses\Ajax.php:24
noprivwp_ajax_consolety_click_recordclasses\Ajax.php:25
WordPress Hooks 19
actionadd_meta_boxesclasses\Admin\Posts\ConsoletyExportCheckbox.php:18
actionsave_postclasses\Admin\Posts\ConsoletyExportCheckbox.php:19
actionrest_api_initclasses\API.php:40
actionrest_api_initclasses\API.php:58
actionrest_api_initclasses\API.php:67
actionrest_api_initclasses\API.php:76
filterthe_contentclasses\Frontend\DisplayBlock.php:20
actionwp_headclasses\Frontend\SettingsDesignBlock.php:22
actionadmin_initclasses\Frontend\SettingsMainBlock.php:22
actionadmin_noticesclasses\Initialization.php:30
actionadmin_menuconsolety.php:47
actionwp_footerconsolety.php:48
actionadmin_enqueue_scriptsconsolety.php:49
actionplugins_loadedconsolety.php:50
actionplugins_loadedconsolety.php:51
actionadmin_initconsolety.php:52
actionpost_updatedconsolety.php:53
actiontransition_post_statusconsolety.php:55
actiondelete_postconsolety.php:57
Maintenance & Trust

Consolety – SEO plugin for Traffic, Authority & Backlinks Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 17, 2021
PHP min version7.2
Downloads15K

Community Trust

Rating100/100
Number of ratings8
Active installs50
Developer Profile

Consolety – SEO plugin for Traffic, Authority & Backlinks Developer Profile

Marijan Karajanov

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Consolety – SEO plugin for Traffic, Authority & Backlinks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/consolety/css/admin.css/wp-content/plugins/consolety/js/admin.js
Version Parameters
consolety-admin?ver=

HTML / DOM Fingerprints

CSS Classes
consolety-styles-color
Data Attributes
data-default-color
JS Globals
consolety_reportconsolety_click_record
FAQ

Frequently Asked Questions about Consolety – SEO plugin for Traffic, Authority & Backlinks