Instant Performance & SEO Security & Risk Analysis

wordpress.org/plugins/instant-seo

Improve your site SEO and performance.

40 active installs v2.0 PHP 5.2.4+ WP 4.2+ Updated Mar 5, 2021
instantperformanceseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Instant Performance & SEO Safe to Use in 2026?

Generally Safe

Score 85/100

Instant Performance & SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The Instant-SEO v2.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and no file operations or external HTTP requests are present. Furthermore, the vulnerability history is clean, with no known CVEs. This suggests a well-developed plugin with good coding practices in critical areas like database interaction and data sanitization.

However, a significant concern arises from the complete lack of output escaping. With two identified outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper escaping can be manipulated by attackers to inject malicious scripts. Additionally, the absence of nonce checks and capability checks, particularly in conjunction with an unknown number of potential entry points (though none were identified as unprotected), leaves room for potential privilege escalation or unauthorized actions if entry points are discovered or added in future updates.

While the plugin's clean vulnerability history is a positive sign, it doesn't negate the immediate risks identified in the code analysis. The lack of output escaping is a critical oversight that needs immediate attention. The plugin's strengths lie in its secure handling of database queries and avoidance of common risky operations, but its weaknesses in output sanitization and potential lack of robust authorization checks on entry points are notable concerns.

Key Concerns

  • Unescaped output detected
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Instant Performance & SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Instant Performance & SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Instant Performance & SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptsinstant-seo.php:11
filterscript_loader_taginstant-seo.php:12
actionadmin_menuinstant-seo.php:26
Maintenance & Trust

Instant Performance & SEO Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 5, 2021
PHP min version5.2.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Instant Performance & SEO Developer Profile

Renat Galyamov

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Instant Performance & SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instant-seo/js/instantpage.js
Script Paths
/wp-content/plugins/instant-seo/js/instantpage.js
Version Parameters
instant-seo/js/instantpage.js?ver=2.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Instant Performance & SEO