Extensions For All In One SEO Pack Security & Risk Analysis

wordpress.org/plugins/extensions-for-all-in-one-seo-pack

Extend the popular SEO plugin All In One SEO Pack. Add new features and modules like 'Link counter'

40 active installs v1.1.0 PHP + WP 3.6.0+ Updated Oct 5, 2019
addonsall-in-one-seo-packextensionsseoseo-link-counter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Extensions For All In One SEO Pack Safe to Use in 2026?

Generally Safe

Score 85/100

Extensions For All In One SEO Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "extensions-for-all-in-one-seo-pack" v1.1.0 presents a generally positive security posture based on the provided static analysis. The absence of any identified CVEs, a clean vulnerability history, and the fact that all SQL queries utilize prepared statements are strong indicators of good development practices. The code also demonstrates a reasonable level of security awareness with the inclusion of a nonce check and two capability checks, suggesting some consideration for authorization. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors common in plugin vulnerabilities.

However, a significant concern arises from the output escaping. With 55% of outputs properly escaped, there's a 45% chance that unsanitized data could be rendered, leading to potential cross-site scripting (XSS) vulnerabilities. While the total number of outputs isn't excessively high, the percentage of unescaped outputs is a notable weakness. The absence of any identified taint flows is a positive sign, but this could be a consequence of limited or no taint analysis being performed, rather than a guarantee of absolute safety. The plugin has a zero attack surface of entry points which is good, but it's worth noting that if any were present without authentication, it would be a major concern.

In conclusion, this plugin appears to be well-maintained with a strong foundation in preventing common vulnerabilities like SQL injection and unauthorized access. The primary area of concern and potential risk lies in the inadequate output escaping, which requires attention to prevent XSS. The lack of reported vulnerabilities historically is a testament to its current stability, but the potential for XSS due to the output escaping issue remains the most significant weakness.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Extensions For All In One SEO Pack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Extensions For All In One SEO Pack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
10
12 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

55% escaped22 total outputs
Attack Surface

Extensions For All In One SEO Pack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionplugins_loadedadmin\check-main-plugin-exists.php:3
actionadmin_noticesadmin\check-main-plugin-exists.php:7
filteraioseop_module_listadmin\class-extensions-for-all-in-one-seo-pack-module-manager.php:51
filteraioseop_module_infoadmin\class-extensions-for-all-in-one-seo-pack-module-manager.php:52
actionaiosp_feature_manager_settings_updateadmin\class-extensions-for-all-in-one-seo-pack-module-manager.php:59
actionaiosp_feature_manager_settings_footeradmin\class-extensions-for-all-in-one-seo-pack-module-manager.php:62
actionadmin_enqueue_scriptsmodules\link_counter\aioseopext_link_counter.php:144
actionadmin_initmodules\link_counter\class-aioseopext-link-counter-column-manager.php:32
actionadmin_headmodules\link_counter\class-aioseopext-link-counter-column-manager.php:70
filtermanage_pages_columnsmodules\link_counter\class-aioseopext-link-counter-column-manager.php:73
filtermanage_posts_columnsmodules\link_counter\class-aioseopext-link-counter-column-manager.php:77
actionmanage_pages_custom_columnmodules\link_counter\class-aioseopext-link-counter-column-manager.php:83
actionmanage_posts_custom_columnmodules\link_counter\class-aioseopext-link-counter-column-manager.php:85
actionpre_get_postsmodules\link_counter\class-aioseopext-link-counter-column-manager.php:88
actionadmin_initmodules\link_counter\class-aioseopext-link-counter-processor.php:106
actionpublish_postmodules\link_counter\class-aioseopext-link-counter-processor.php:117
actiondelete_postmodules\link_counter\class-aioseopext-link-counter-processor.php:118
actiontransition_post_statusmodules\link_counter\class-aioseopext-link-counter-processor.php:119
actionadmin_bar_menumodules\useful_links\aioseopext_useful_links.php:51
Maintenance & Trust

Extensions For All In One SEO Pack Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 5, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Extensions For All In One SEO Pack Developer Profile

Md Jahidul Islam

6 plugins · 2K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Extensions For All In One SEO Pack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extensions-for-all-in-one-seo-pack/admin/css/extensions-for-all-in-one-seo-pack-admin.css/wp-content/plugins/extensions-for-all-in-one-seo-pack/admin/js/extensions-for-all-in-one-seo-pack-admin.js
Script Paths
/wp-content/plugins/extensions-for-all-in-one-seo-pack/admin/js/extensions-for-all-in-one-seo-pack-admin.js
Version Parameters
extensions-for-all-in-one-seo-pack/admin/css/extensions-for-all-in-one-seo-pack-admin.css?ver=extensions-for-all-in-one-seo-pack/admin/js/extensions-for-all-in-one-seo-pack-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
aioseopext-link-counter-stat-wrapperaioseopext-link-counter-process-wrapper
FAQ

Frequently Asked Questions about Extensions For All In One SEO Pack