MetaRobots by SEO-Sign Security & Risk Analysis

wordpress.org/plugins/meta-robots-by-seo-sign

The easiest way to manage meta robots tag.

100 active installs v1.0.0 PHP + WP 3.0.1+ Updated Apr 7, 2015
crawlerseditorgooglemeta-robotsrobots-txt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MetaRobots by SEO-Sign Safe to Use in 2026?

Generally Safe

Score 85/100

MetaRobots by SEO-Sign has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "meta-robots-by-seo-sign" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the plugin has a seemingly small attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it demonstrates good practices by using prepared statements for all its SQL queries and having no known vulnerabilities or CVEs in its history. This suggests a developer who is mindful of common attack vectors like SQL injection and has maintained a clean security record so far.

However, significant concerns arise from the static analysis. The lack of any output escaping for its detected outputs is a critical weakness. This means that any data displayed to users could potentially be manipulated, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed four flows with unsanitized paths, which, although not classified as critical or high severity in this instance, still indicate potential issues with how data is handled and could be exploited in conjunction with other weaknesses. The absence of nonce and capability checks also presents a risk, as it suggests that entry points, if they were to exist, might not be adequately protected against unauthorized access or manipulation.

In conclusion, while the plugin boasts a clean vulnerability history and good database practices, the complete lack of output escaping and the presence of unsanitized data flows are major security red flags. These issues, coupled with the absence of capability and nonce checks, significantly elevate the risk profile. Developers should prioritize addressing the output escaping and taint flow issues to improve the plugin's overall security.

Key Concerns

  • Unescaped output detected
  • Unsanitized paths in taint flows (4 flows)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

MetaRobots by SEO-Sign Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MetaRobots by SEO-Sign Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
10
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
metarobots_mrs (metarobots-wp.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MetaRobots by SEO-Sign Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headmetarobots-wp.php:127
actionadmin_menusettings.php:2
actionadmin_initsettings.php:6
Maintenance & Trust

MetaRobots by SEO-Sign Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 7, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

MetaRobots by SEO-Sign Developer Profile

Artem Pilipets

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MetaRobots by SEO-Sign

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meta-robots-by-seo-sign/metarobots.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MetaRobots by SEO-Sign