
Keyword Landing Page Generator (Free) Security & Risk Analysis
wordpress.org/plugins/keyword-landing-page-generatorAllows you to have one landing page, with different versions depending on the keyword -- so you can show each visitor a customized version of it!
Is Keyword Landing Page Generator (Free) Safe to Use in 2026?
Generally Safe
Score 85/100Keyword Landing Page Generator (Free) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The keyword-landing-page-generator plugin, version 1.01, presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase in those areas. It also correctly limits its attack surface with no exposed AJAX handlers or REST API routes. However, significant concerns arise from the static analysis. The presence of three 'unserialize' calls is a major red flag, as unserialization of untrusted data can lead to remote code execution vulnerabilities. Furthermore, over a quarter of the output escaping is not properly handled, creating potential for cross-site scripting (XSS) vulnerabilities. The taint analysis indicating flows with unsanitized paths, even without critical or high severity findings, warrants attention as it highlights potential areas where data could be manipulated. The absence of nonce checks on the single shortcode entry point is also a weakness.
While the plugin's lack of historical vulnerabilities is encouraging, the static analysis reveals inherent risks that require immediate attention. The identified 'unserialize' functions are particularly concerning and could be exploited if user-controlled data is passed to them without proper validation. The unescaped output also poses an XSS risk. The taint analysis, though not reporting critical issues, suggests that data sanitization might not be consistently applied, which can pave the way for other vulnerabilities. The plugin’s overall security is moderately concerning due to these specific code-level risks, despite its otherwise clean history and limited attack surface.
Key Concerns
- Dangerous function call: unserialize
- Output escaping is not consistently applied
- Flows with unsanitized paths detected
- Missing nonce check on shortcode entry point
Keyword Landing Page Generator (Free) Security Vulnerabilities
Keyword Landing Page Generator (Free) Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Keyword Landing Page Generator (Free) Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Keyword Landing Page Generator (Free) Maintenance & Trust
Maintenance Signals
Community Trust
Keyword Landing Page Generator (Free) Alternatives
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
Tracking Code Manager
tracking-code-manager
A plugin to manage ALL of your tracking code and conversion pixels. Compatible with Facebook Ads, Google Adwords, WooCommerce, Easy Digital Downloads, …
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Quick Adsense
quick-adsense
Quick Adsense offers a quicker & flexible way to insert Google Adsense or any Ads code into a blog post.
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
enhanced-e-commerce-for-woocommerce-store
Track GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
Keyword Landing Page Generator (Free) Developer Profile
9 plugins · 8K total installs
How We Detect Keyword Landing Page Generator (Free)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/keyword-landing-page-generator/css/style.css/wp-content/plugins/keyword-landing-page-generator/js/script.js/wp-content/plugins/keyword-landing-page-generator/js/script.jskeyword-landing-page-generator/css/style.css?ver=keyword-landing-page-generator/js/script.js?ver=HTML / DOM Fingerprints
lpwarning[wpsos key=