Do Shortcodes for Rank Math SEO Security & Risk Analysis

wordpress.org/plugins/do-shortcodes-for-rank-math-seo

Display shortcodes in the title, description, Facebook and Twitter fields, and other locations for Rank Math SEO.

1K active installs v1.2.4 PHP + WP 4.0+ Updated Apr 16, 2025
applyrank-mathseoshortcodeshortcodes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Do Shortcodes for Rank Math SEO Safe to Use in 2026?

Generally Safe

Score 100/100

Do Shortcodes for Rank Math SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "do-shortcodes-for-rank-math-seo" v1.2.4 exhibits a strong security posture based on the provided static analysis. The complete absence of identified attack vectors such as AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication, is a significant strength. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests contributes to a reduced attack surface. The fact that all SQL queries utilize prepared statements is also a positive indicator of secure coding practices.

However, a critical concern arises from the significantly low percentage of properly escaped output (2%). With 42 total outputs, this implies that 98% of the plugin's output is potentially vulnerable to cross-site scripting (XSS) attacks. This is a considerable risk, as unsanitized output can lead to malicious code being injected into web pages, compromising user sessions and data. The absence of any vulnerability history is reassuring but should be viewed in conjunction with the identified output escaping issue, suggesting that current vulnerabilities might be inherent in the code rather than historical regressions.

In conclusion, while the plugin has strong foundational security measures in place regarding entry points and data handling (SQL), the widespread lack of output escaping presents a significant and immediate risk of XSS vulnerabilities. This weakness overshadows the plugin's otherwise secure design, making careful attention to output sanitization imperative.

Key Concerns

  • Low output escaping percentage (2%)
Vulnerabilities
None known

Do Shortcodes for Rank Math SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Do Shortcodes for Rank Math SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

2% escaped42 total outputs
Attack Surface

Do Shortcodes for Rank Math SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitdenra-plugins\classes\Plugin.php:56
actioninitplugin\classes\DoShortcodesRankMathSEO.php:42
Maintenance & Trust

Do Shortcodes for Rank Math SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 16, 2025
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs1K
Developer Profile

Do Shortcodes for Rank Math SEO Developer Profile

Denra.com

3 plugins · 11K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Do Shortcodes for Rank Math SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/do-shortcodes-for-rank-math-seo/static/css/user.css/wp-content/plugins/do-shortcodes-for-rank-math-seo/static/js/user.js
Script Paths
/wp-content/plugins/do-shortcodes-for-rank-math-seo/static/js/user.js
Version Parameters
do-shortcodes-for-rank-math-seo/static/css/user.css?ver=do-shortcodes-for-rank-math-seo/static/js/user.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Do Shortcodes for Rank Math SEO