
MetaRobots by SEO-Sign Security & Risk Analysis
wordpress.org/plugins/meta-robots-by-seo-signThe easiest way to manage meta robots tag.
Is MetaRobots by SEO-Sign Safe to Use in 2026?
Generally Safe
Score 85/100MetaRobots by SEO-Sign has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "meta-robots-by-seo-sign" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the plugin has a seemingly small attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it demonstrates good practices by using prepared statements for all its SQL queries and having no known vulnerabilities or CVEs in its history. This suggests a developer who is mindful of common attack vectors like SQL injection and has maintained a clean security record so far.
However, significant concerns arise from the static analysis. The lack of any output escaping for its detected outputs is a critical weakness. This means that any data displayed to users could potentially be manipulated, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed four flows with unsanitized paths, which, although not classified as critical or high severity in this instance, still indicate potential issues with how data is handled and could be exploited in conjunction with other weaknesses. The absence of nonce and capability checks also presents a risk, as it suggests that entry points, if they were to exist, might not be adequately protected against unauthorized access or manipulation.
In conclusion, while the plugin boasts a clean vulnerability history and good database practices, the complete lack of output escaping and the presence of unsanitized data flows are major security red flags. These issues, coupled with the absence of capability and nonce checks, significantly elevate the risk profile. Developers should prioritize addressing the output escaping and taint flow issues to improve the plugin's overall security.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint flows (4 flows)
- Missing nonce checks
- Missing capability checks
MetaRobots by SEO-Sign Security Vulnerabilities
MetaRobots by SEO-Sign Code Analysis
Output Escaping
Data Flow Analysis
MetaRobots by SEO-Sign Attack Surface
WordPress Hooks 3
Maintenance & Trust
MetaRobots by SEO-Sign Maintenance & Trust
Maintenance Signals
Community Trust
MetaRobots by SEO-Sign Alternatives
Microthemer Lite – Visual Editor to Customize CSS
microthemer
A visual editor to customize the CSS styling of anything on your site - from Google fonts to responsive layouts.
Fonts
fonts
Add More Font To Your WordPress Editor
Better Robots.txt – AI-Ready Crawl Control & Bot Governance
better-robots-txt
Replace the default WordPress robots.txt workflow with a smarter, structured version you can preview before publishing, with Free, Pro, and Premium ed …
Multipart robots.txt editor
multipart-robotstxt-editor
Customize your site's robots.txt and include remote content to it
Block AI Crawlers
block-ai-crawlers
Tell AI (Artificial Intelligence) companies not to scrape your site for their AI products.
MetaRobots by SEO-Sign Developer Profile
1 plugin · 100 total installs
How We Detect MetaRobots by SEO-Sign
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meta-robots-by-seo-sign/metarobots.php