
LH SEO Meta Tags Security & Risk Analysis
wordpress.org/plugins/lh-seo-meta-tagsBasic SEO meta tags, decisions not options
Is LH SEO Meta Tags Safe to Use in 2026?
Generally Safe
Score 85/100LH SEO Meta Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-seo-meta-tags" plugin, version 1.01, demonstrates a generally positive security posture based on the provided static analysis. The absence of identifiable AJAX handlers, REST API routes, shortcodes, and cron events contributing to the attack surface is a significant strength. Furthermore, the code's adherence to using prepared statements for all SQL queries and the presence of a nonce check indicate good development practices in these critical areas. The plugin also shows no history of known vulnerabilities, which is a strong indicator of past security consciousness.
However, a notable concern arises from the output escaping. With only 20% of 15 total outputs being properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully, could be injected into the page's output and executed by a user's browser. The lack of capability checks on any entry points, while the entry points are currently zero, could become a risk if future updates introduce new functionalities that are not adequately secured against unauthorized access.
In conclusion, while the plugin avoids many common pitfalls like raw SQL queries and a large attack surface, the poor handling of output escaping presents a tangible and immediate risk. The absence of vulnerability history is reassuring, but it does not mitigate the identified code-level weaknesses. Addressing the output escaping issues should be the top priority to improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
- Lack of capability checks on entry points
LH SEO Meta Tags Security Vulnerabilities
LH SEO Meta Tags Code Analysis
Output Escaping
LH SEO Meta Tags Attack Surface
WordPress Hooks 6
Maintenance & Trust
LH SEO Meta Tags Maintenance & Trust
Maintenance Signals
Community Trust
LH SEO Meta Tags Alternatives
MetaMax
metamax
MetaMax automagically inserts meta tags in your html to make your site more SEO friendly.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
SiteSEO – SEO Simplified
siteseo
SiteSEO is an easy, fast and powerful SEO plugin for WordPress. Unlock your Website's potential and Maximize your online visibility with our SiteSEO!
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
VS Meta Description
very-simple-meta-description
With this lightweight plugin you can add a meta description to your website.
LH SEO Meta Tags Developer Profile
77 plugins · 15K total installs
How We Detect LH SEO Meta Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-seo-meta-tags/css/style.csslh-seo-meta-tags/style.css?ver=HTML / DOM Fingerprints
<!-- begin LH SEO meta output --><!-- end LH SEO meta output -->name="lh_html_meta_tags-noindex"id="lh_html_meta_tags-noindex"name="lh_html_meta_tags-post_object-desc"name="lh_html_meta_tags-metabox-nonce"name="lh_html_meta_tags-site_keywords"name="lh_html_meta_tags-google_meta_tag_id"