Metapilot Smart SEO Security & Risk Analysis

wordpress.org/plugins/metapilot-smart-seo

AI-powered SEO plugin with meta generation, content analysis, schema markup, XML sitemaps, redirect manager, and robots.txt editor.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Mar 23, 2026
ai-seoredirectsschema-markupseoxml-sitemap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Metapilot Smart SEO Safe to Use in 2026?

Generally Safe

Score 100/100

Metapilot Smart SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'metapilot-smart-seo' plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and properly escaping all output. The absence of known vulnerabilities in its history is also a significant strength, suggesting a generally well-maintained and secure codebase to date. However, a notable concern arises from the plugin's attack surface. With 10 AJAX handlers, a significant portion (5) lack proper authentication checks. This leaves these entry points potentially vulnerable to unauthorized access and manipulation if an attacker can trigger them. Furthermore, the taint analysis revealed one flow with a high severity, indicating a potential path for malicious data to be processed in an unsafe manner. The presence of unsanitized paths in 3 out of 4 analyzed flows, even if not all are critical or high severity, warrants attention as it suggests a potential for vulnerabilities to be introduced if these paths are exploited.

Key Concerns

  • 5 AJAX handlers without auth checks
  • 1 high severity taint flow
  • 3 flows with unsanitized paths
Vulnerabilities
None known

Metapilot Smart SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Metapilot Smart SEO Release Timeline

v1.0
v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Metapilot Smart SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
64 prepared
Unescaped Output
5
1380 escaped
Nonce Checks
18
Capability Checks
12
File Operations
1
External Requests
4
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared64 total queries

Output Escaping

100% escaped1385 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
handle_redirect_actions (admin/class-redirect-admin.php:173)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Metapilot Smart SEO Attack Surface

Entry Points10
Unprotected5

AJAX Handlers 10

authwp_ajax_mpseo_generate_metaadmin/class-metabox.php:562
authwp_ajax_mpseo_analyze_contentadmin/class-metabox.php:563
authwp_ajax_mpseo_calculate_scoreadmin/class-metabox.php:564
authwp_ajax_mpseo_update_analysisadmin/class-metabox.php:565
authwp_ajax_mpseo_flush_sitemapadmin/class-sitemap-admin.php:24
authwp_ajax_mpseo_generate_metaincludes/class-metapilot-smart-seo.php:133
authwp_ajax_mpseo_analyze_contentincludes/class-metapilot-smart-seo.php:134
authwp_ajax_mpseo_calculate_scoreincludes/class-metapilot-smart-seo.php:135
authwp_ajax_mpseo_preview_robotsincludes/class-metapilot-smart-seo.php:143
authwp_ajax_mpseo_reset_robotsincludes/class-metapilot-smart-seo.php:144
WordPress Hooks 36
actionadmin_initadmin/class-redirect-admin.php:54
actionadmin_initadmin/class-redirect-admin.php:55
actionadmin_initadmin/class-sitemap-admin.php:23
actionupdate_option_mpseo_sitemap_enabledadmin/class-sitemap-admin.php:25
actionupdate_option_mpseo_sitemap_post_typesadmin/class-sitemap-admin.php:26
actionadmin_enqueue_scriptsincludes/class-metapilot-smart-seo.php:115
actionadmin_enqueue_scriptsincludes/class-metapilot-smart-seo.php:116
actionadmin_menuincludes/class-metapilot-smart-seo.php:120
actionadmin_initincludes/class-metapilot-smart-seo.php:121
actionadd_meta_boxesincludes/class-metapilot-smart-seo.php:125
actionsave_postincludes/class-metapilot-smart-seo.php:126
actionadmin_noticesincludes/class-metapilot-smart-seo.php:130
actionadmin_initincludes/class-metapilot-smart-seo.php:142
actionadmin_initincludes/class-metapilot-smart-seo.php:148
actionadmin_enqueue_scriptsincludes/class-metapilot-smart-seo.php:149
actioninitincludes/class-metapilot-smart-seo.php:161
actionwp_headincludes/class-metapilot-smart-seo.php:164
actionwp_headincludes/class-metapilot-smart-seo.php:167
actionwp_headincludes/class-metapilot-smart-seo.php:170
actionwp_enqueue_scriptsincludes/class-metapilot-smart-seo.php:173
filterscript_loader_tagincludes/class-metapilot-smart-seo.php:174
actioninitincludes/class-metapilot-smart-seo.php:181
filterpre_get_document_titleincludes/class-metapilot-smart-seo.php:184
filterdocument_title_partsincludes/class-metapilot-smart-seo.php:185
filterrobots_txtincludes/class-metapilot-smart-seo.php:189
actionwp_headincludes/class-metapilot-smart-seo.php:193
actioninitincludes/redirects/class-redirect-handler.php:50
actionwpincludes/redirects/class-redirect-handler.php:51
actionplugins_loadedincludes/sitemap/class-sitemap-loader.php:46
actioninitincludes/sitemap/class-sitemap-manager.php:72
actiontemplate_redirectincludes/sitemap/class-sitemap-manager.php:75
filterquery_varsincludes/sitemap/class-sitemap-manager.php:78
actionpublish_postincludes/sitemap/class-sitemap-manager.php:81
actionpublish_pageincludes/sitemap/class-sitemap-manager.php:82
filterrobots_txtincludes/sitemap/class-sitemap-manager.php:85
actionupdate_option_mpseo_sitemap_enabledincludes/sitemap/class-sitemap-manager.php:88
Maintenance & Trust

Metapilot Smart SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 23, 2026
PHP min version7.4
Downloads70

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Metapilot Smart SEO Developer Profile

wpstrativ

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Metapilot Smart SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/metapilot-smart-seo/assets/css/admin.css/wp-content/plugins/metapilot-smart-seo/assets/css/metabox.css/wp-content/plugins/metapilot-smart-seo/assets/css/settings.css/wp-content/plugins/metapilot-smart-seo/assets/css/admin-views.css/wp-content/plugins/metapilot-smart-seo/assets/js/character-counter.js/wp-content/plugins/metapilot-smart-seo/assets/js/metabox.js/wp-content/plugins/metapilot-smart-seo/assets/js/admin.js/wp-content/plugins/metapilot-smart-seo/assets/js/settings.js+1 more
Script Paths
/wp-content/plugins/metapilot-smart-seo/assets/js/character-counter.js/wp-content/plugins/metapilot-smart-seo/assets/js/metabox.js/wp-content/plugins/metapilot-smart-seo/assets/js/admin.js/wp-content/plugins/metapilot-smart-seo/assets/js/settings.js/wp-content/plugins/metapilot-smart-seo/assets/js/admin-views.js
Version Parameters
metapilot-smart-seo/assets/css/admin.css?ver=metapilot-smart-seo/assets/css/metabox.css?ver=metapilot-smart-seo/assets/css/settings.css?ver=metapilot-smart-seo/assets/css/admin-views.css?ver=metapilot-smart-seo/assets/js/character-counter.js?ver=metapilot-smart-seo/assets/js/metabox.js?ver=metapilot-smart-seo/assets/js/admin.js?ver=metapilot-smart-seo/assets/js/settings.js?ver=metapilot-smart-seo/assets/js/admin-views.js?ver=

HTML / DOM Fingerprints

CSS Classes
metapilot-smart-seo
JS Globals
mpseoDatampseoViewsData
FAQ

Frequently Asked Questions about Metapilot Smart SEO