NASHR SEO Security & Risk Analysis

wordpress.org/plugins/nashr-seo

Simple and easy way to optimize your wordpress website for search engines and social media websites

10 active installs v1.6.1 PHP + WP 3.4.0+ Updated Apr 25, 2017
bingcanonicaldescriptiongooglegoogle-webmaster-tools
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NASHR SEO Safe to Use in 2026?

Generally Safe

Score 85/100

NASHR SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The nashr-seo plugin version 1.6.1 exhibits a mixed security posture. While it demonstrates a commitment to secure database practices by using prepared statements for all SQL queries and has no recorded historical vulnerabilities, significant concerns arise from its attack surface and handling of potentially dangerous functions. The presence of two unprotected AJAX handlers presents a direct pathway for unauthenticated attackers to interact with the plugin's functionality, posing a considerable risk. Furthermore, the use of the `unserialize` function without explicit sanitization or validation of the input it processes is a critical security vulnerability. This can lead to remote code execution if an attacker can control the serialized data passed to this function. The taint analysis, while showing no critical or high severity flows, is limited by the total number of flows analyzed (10). The 100% of flows with unsanitized paths is a strong indicator of potential issues, even if not currently exploited in the analyzed scope. The low percentage of properly escaped output (12%) also suggests a heightened risk of Cross-Site Scripting (XSS) vulnerabilities across various output points.

Key Concerns

  • Unprotected AJAX handlers
  • Use of unserialize without input validation
  • Low percentage of properly escaped output
  • All analyzed flows have unsanitized paths
Vulnerabilities
None known

NASHR SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NASHR SEO Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
107
14 escaped
Nonce Checks
1
Capability Checks
2
File Operations
4
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserializereturn unserialize($fileContent);includes\mnbaa_functions.php:8

Output Escaping

12% escaped121 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

10 flows10 with unsanitized paths
mnbaa_seo_get_word_count (controllers\ajax_functions.php:2)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

NASHR SEO Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_mnbaa_seo_get_word_countincludes\wp_functions.php:130
authwp_ajax_mnbaa_seo_get_archive_metaincludes\wp_functions.php:136
WordPress Hooks 16
actionadmin_menuincludes\wp_functions.php:7
actionadd_meta_boxesincludes\wp_functions.php:41
actionadmin_menuincludes\wp_functions.php:42
actionadd_meta_boxesincludes\wp_functions.php:74
actionadmin_menuincludes\wp_functions.php:75
actionadd_meta_boxesincludes\wp_functions.php:120
actionadmin_enqueue_scriptsincludes\wp_functions.php:121
actionsave_postincludes\wp_functions.php:122
actionwp_headincludes\wp_functions.php:123
filterwp_titleincludes\wp_functions.php:125
actionadmin_menuincludes\wp_functions.php:126
actionadmin_menuincludes\wp_functions.php:127
actionadmin_menuincludes\wp_functions.php:128
actionadmin_menuincludes\wp_functions.php:129
actionedit_termincludes\wp_functions.php:134
actionadmin_enqueue_scriptsincludes\wp_functions.php:135
Maintenance & Trust

NASHR SEO Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 25, 2017
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

NASHR SEO Developer Profile

mnbaaco

2 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NASHR SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nashr-seo/js/custom-js.js/wp-content/plugins/nashr-seo/js/limit.js/wp-content/plugins/nashr-seo/js/selectall.js/wp-content/plugins/nashr-seo/js/mytabs.js/wp-content/plugins/nashr-seo/js/jquery-ui.js/wp-content/plugins/nashr-seo/js/nashr-autocomplete.js/wp-content/plugins/nashr-seo/js/ajax-js.js/wp-content/plugins/nashr-seo/js/ajax-nashr.js+9 more
Script Paths
/wp-content/plugins/nashr-seo/js/custom-js.js/wp-content/plugins/nashr-seo/js/limit.js/wp-content/plugins/nashr-seo/js/selectall.js/wp-content/plugins/nashr-seo/js/mytabs.js/wp-content/plugins/nashr-seo/js/jquery-ui.js/wp-content/plugins/nashr-seo/js/nashr-autocomplete.js+2 more

HTML / DOM Fingerprints

CSS Classes
seo_divmytabsnav-tabnav-tab-activecategory-tabs
Data Attributes
id="mytabs"id="seo_div"id="wpseo-tabs"id="post_id"id="search_title"id="prefix"
JS Globals
ajaxmyAjax
REST Endpoints
/wp-json/nashr-seo/
Shortcode Output
<div id="mytabs" class="">License key is Invalidinsert secret key hereget secret key here
FAQ

Frequently Asked Questions about NASHR SEO