GrowthSEO – Content Sync Security & Risk Analysis

wordpress.org/plugins/growthseo-content-sync

Secure REST endpoint to publish posts from GrowthSEO backend via API key.

0 active installs v1.0.14 PHP 7.4+ WP 5.6+ Updated Unknown
headlesspublishingrest-apiwebhook
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is GrowthSEO – Content Sync Safe to Use in 2026?

Generally Safe

Score 100/100

GrowthSEO – Content Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "growthseo-content-sync" plugin version 1.0.14 exhibits a mixed security posture. On the positive side, the plugin does not appear to have any known historical vulnerabilities (CVEs) and does not utilize dangerous functions, file operations, or external HTTP requests, which are common sources of security flaws. The use of prepared statements for SQL queries is also a good practice, although the percentage is not exceptionally high. However, there are notable areas of concern.

The static analysis reveals a single unprotected REST API route, which represents a direct entry point that could be exploited if it handles user-supplied data without proper validation or authorization. While there are no critical taint flows identified, the lack of proper output escaping on over half of the identified outputs is a significant weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is not properly sanitized before being displayed. The absence of nonce checks on AJAX handlers and a lack of comprehensive capability checks on REST API routes further contribute to potential security weaknesses.

Given the absence of historical vulnerabilities, it suggests that the developers may be diligent in addressing past issues or that the plugin hasn't been a target. Nevertheless, the identified weaknesses in the current version, particularly the unprotected REST API endpoint and insufficient output escaping, warrant attention. Addressing these issues would significantly strengthen the plugin's security posture.

Key Concerns

  • Unprotected REST API route
  • Insufficient output escaping
  • Missing nonce checks
  • Limited capability checks on REST API
  • SQL queries not fully prepared
Vulnerabilities
None known

GrowthSEO – Content Sync Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GrowthSEO – Content Sync Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
28
31 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

53% escaped59 total outputs
Attack Surface
1 unprotected

GrowthSEO – Content Sync Attack Surface

Entry Points2
Unprotected1

REST API Routes 2

GET/wp-json/growthseo/v1/pingincludes\rest.php:5
POST/wp-json/growthseo/v1/publishincludes\rest.php:11
WordPress Hooks 8
actionadmin_menuincludes\admin.php:4
actionadmin_enqueue_scriptsincludes\admin.php:26
actionadmin_enqueue_scriptsincludes\admin.php:38
actionadmin_initincludes\admin.php:135
actionrest_api_initincludes\rest.php:4
filterwp_kses_allowed_htmlincludes\rest.php:145
actionwp_headincludes\rest.php:497
filterwp_kses_allowed_htmlincludes\rest.php:524
Maintenance & Trust

GrowthSEO – Content Sync Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads164

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GrowthSEO – Content Sync Developer Profile

meetcpatel907

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GrowthSEO – Content Sync

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/growthseo-content-sync/growthseo-logo.png
Version Parameters
growthseo-menu-icongrowthseo-admin

HTML / DOM Fingerprints

CSS Classes
gseo-wrapgseo-herogseo-cardgseo-fieldgseo-labelgseo-inputgseo-descgseo-input-group+6 more
Data Attributes
data-copy-target
JS Globals
growthseoAdmin
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about GrowthSEO – Content Sync