JorgeCastro Security & Risk Analysis

wordpress.org/plugins/jorgecastro

JorgeCastro is a complete AI-powered SEO agent that automatically manages, optimizes, and scales your entire website’s SEO using modern techniques and …

0 active installs v1.1.0 PHP 7.2+ WP 5.0+ Updated Mar 1, 2026
ai-seoblog-generatorcontent-automationtechnical-seoyoutube-seo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JorgeCastro Safe to Use in 2026?

Generally Safe

Score 100/100

JorgeCastro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "jorgecastro" v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, unsanitized taint flows, and the consistent use of prepared statements for all SQL queries are positive indicators. Furthermore, the plugin demonstrates good practices regarding output escaping, with a high percentage of outputs properly handled. The presence of nonce and capability checks for its entry points, though limited in number, also suggests an awareness of security fundamentals.

However, the plugin's attack surface, while small, is entirely reliant on these checks. With only two AJAX handlers and no REST API routes, shortcodes, or cron events, there are very few opportunities for attackers to interact with the plugin. This limited scope might mask potential vulnerabilities if more complex interactions were introduced. The plugin's vulnerability history is clean, showing no recorded CVEs, which is a strong positive. This, combined with the static analysis findings, suggests the plugin has likely been developed with security in mind or has been effectively secured over time.

In conclusion, "jorgecastro" v1.1.0 appears to be a relatively secure plugin. Its strengths lie in its adherence to secure coding practices for the identified entry points and its clean vulnerability history. The main area for caution is the limited attack surface, which, while currently protected, could become a concern if the plugin's functionality expands without maintaining rigorous security checks. For its current state and scope, the risk is low.

Vulnerabilities
None known

JorgeCastro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

JorgeCastro Release Timeline

v1.1.0Current
Code Analysis
Analyzed Mar 17, 2026

JorgeCastro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
200 escaped
Nonce Checks
5
Capability Checks
4
File Operations
6
External Requests
2
Bundled Libraries
0

Output Escaping

93% escaped214 total outputs
Attack Surface

JorgeCastro Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_jorgecastro_app_connectionclasses\Admin\SettingsForm.php:21
authwp_ajax_jorgecastro-notifyjorgecastro.php:74
WordPress Hooks 6
actionadmin_menuclasses\Admin\SettingsForm.php:19
actionadmin_footerclasses\Admin\SettingsForm.php:105
actionadmin_footerclasses\Admin\SettingsForm.php:125
actionrestrict_manage_postsjorgecastro.php:65
actionpre_get_postsjorgecastro.php:66
actionrest_api_initjorgecastro.php:79
Maintenance & Trust

JorgeCastro Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 1, 2026
PHP min version7.2
Downloads288

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

JorgeCastro Developer Profile

castromind

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JorgeCastro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jorgecastro/dist/assets/index-7b625390.js/wp-content/plugins/jorgecastro/dist/assets/index-0b4b8b96.css/wp-content/plugins/jorgecastro/admin/css/admin.css/wp-content/plugins/jorgecastro/admin/js/admin.js
Script Paths
/wp-content/plugins/jorgecastro/admin/js/admin.js
Version Parameters
jorgecastro/dist/assets/index-7b625390.js?ver=jorgecastro/dist/assets/index-0b4b8b96.css?ver=jorgecastro/admin/css/admin.css?ver=jorgecastro/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
jorgecastro-settings-pagejorgecastro-api-key-inputjorgecastro-toggle-switch
Data Attributes
data-jorgecastro-setting
JS Globals
jorgecastro_admin
REST Endpoints
/wp-json/jorgecastro/v1/webhook/wp-json/jorgecastro/v1/log/wp-json/jorgecastro/v1/bulk-posts/wp-json/jorgecastro/v1/posts/update/wp-json/jorgecastro/v1/posts/delete/wp-json/jorgecastro/v1/woocommerce-products/wp-json/jorgecastro/v1/woocommerce-products/update/wp-json/jorgecastro/v1/woocommerce-categories
FAQ

Frequently Asked Questions about JorgeCastro