Hydori SEO – AI-Powered SEO Automation Security & Risk Analysis

wordpress.org/plugins/hydori-seo-ai-powered-seo-automation

Autonomous SEO platform that detects ranking drops, generates AI content fixes, and publishes directly to WordPress. The full closed loop.

0 active installs v2.3.1 PHP 7.4+ WP 5.0+ Updated Mar 26, 2026
ai-seocontent-marketingmultilingualseoseo-audit
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hydori SEO – AI-Powered SEO Automation Safe to Use in 2026?

Generally Safe

Score 100/100

Hydori SEO – AI-Powered SEO Automation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'hydori-seo-ai-powered-seo-automation' plugin v2.3.1 exhibits a concerning security posture due to a significant number of unprotected entry points, specifically 4 AJAX handlers lacking authentication checks. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and proper output escaping, these unprotected AJAX handlers represent a substantial risk. The lack of authorization means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure.

The taint analysis reveals 3 flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, warrants attention. These flows could potentially be exploited if combined with other weaknesses or if an attacker can control the input in a specific way. The absence of any recorded vulnerability history is a positive sign, suggesting a history of secure development or timely patching, but it does not negate the immediate risks identified in the static analysis. Overall, the plugin has some strengths in data handling and SQL security, but the presence of multiple unprotected AJAX endpoints is a critical weakness that significantly elevates the risk profile.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

Hydori SEO – AI-Powered SEO Automation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Hydori SEO – AI-Powered SEO Automation Release Timeline

v2.3.1Current
v2.3.0
Code Analysis
Analyzed Apr 16, 2026

Hydori SEO – AI-Powered SEO Automation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
181 escaped
Nonce Checks
4
Capability Checks
6
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped181 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
send_cors_headers (includes/class-hydori-rest-api.php:233)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Hydori SEO – AI-Powered SEO Automation Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_hydori_test_connectionincludes/class-hydori-sync.php:124
authwp_ajax_hydori_regenerate_keyincludes/class-hydori-sync.php:125
authwp_ajax_hydori_save_settingsincludes/class-hydori-sync.php:126
authwp_ajax_hydori_export_to_hydoriincludes/class-hydori-sync.php:127
WordPress Hooks 10
actionadmin_inithydori-sync.php:161
actionsave_postincludes/class-hydori-export-manager.php:34
actiontransition_post_statusincludes/class-hydori-export-manager.php:37
filterrest_pre_serve_requestincludes/class-hydori-rest-api.php:192
actionadmin_menuincludes/class-hydori-sync.php:117
actionadmin_enqueue_scriptsincludes/class-hydori-sync.php:120
actionadmin_enqueue_scriptsincludes/class-hydori-sync.php:121
actionrest_api_initincludes/class-hydori-sync.php:140
actionrest_api_initincludes/class-hydori-sync.php:143
actioninitincludes/class-hydori-sync.php:146
Maintenance & Trust

Hydori SEO – AI-Powered SEO Automation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.4
Downloads108

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hydori SEO – AI-Powered SEO Automation Developer Profile

ertiqah

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hydori SEO – AI-Powered SEO Automation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hydori-seo-ai-powered-seo-automation/admin/css/hydori-sync-admin.css/wp-content/plugins/hydori-seo-ai-powered-seo-automation/admin/js/hydori-sync-admin.js
Script Paths
/wp-content/plugins/hydori-seo-ai-powered-seo-automation/admin/js/hydori-sync-admin.js
Version Parameters
hydori-seo-ai-powered-seo-automation/admin/css/hydori-sync-admin.css?ver=hydori-seo-ai-powered-seo-automation/admin/js/hydori-sync-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
hydori-settings-sectionhydori-settings-fieldhydori-settings-labelhydori-settings-inputhydori-api-key-inputhydori-save-buttonhydori-sync-statushydori-sync-log+5 more
HTML Comments
<!-- Start Hydori Settings Section --><!-- End Hydori Settings Section --><!-- Start Hydori Settings Field --><!-- End Hydori Settings Field -->+2 more
Data Attributes
data-hydori-settings-sectiondata-hydori-settings-fielddata-hydori-sync-statusdata-hydori-sync-log
JS Globals
hydoriSync
REST Endpoints
/wp-json/hydori/v1/settings/wp-json/hydori/v1/sync/manual/wp-json/hydori/v1/log
FAQ

Frequently Asked Questions about Hydori SEO – AI-Powered SEO Automation