NFCBC SEO Light Security & Risk Analysis

wordpress.org/plugins/nfcbc-seo-light

NFCBC SEO Light - The light version of [Nofollow Case by Case](http://www.fob-marketing.de/marketing-seo-blog/wordpress-nofollow-seo-plugin-nofollow-c …

10 active installs v1.0 PHP + WP 1.5+ Updated Jul 12, 2009
commentsdofollowfollownofollownolink
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NFCBC SEO Light Safe to Use in 2026?

Generally Safe

Score 85/100

NFCBC SEO Light has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "nfcbc-seo-light" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, output is properly escaped, and there are no file operations or external HTTP requests. Furthermore, the plugin doesn't appear to expose a direct attack surface through AJAX, REST API, shortcodes, or cron events, and all identified potential entry points (though none exist) would have been protected. This suggests adherence to good security development practices.

The lack of any recorded CVEs and the absence of any findings in the taint analysis further reinforce this positive assessment. No vulnerability history indicates that the plugin has not had public security issues, which is a significant positive indicator. However, the complete absence of capability checks and nonce checks is a point of concern. While there are no identified entry points *currently*, any future additions or unforeseen interactions could become vulnerable if these fundamental security mechanisms are not implemented.

In conclusion, "nfcbc-seo-light" v1.0 presents a very low immediate risk based on the provided data. Its strong adherence to secure coding practices in areas like SQL and output handling is commendable. The primary weakness, and a potential area for future risk, lies in the complete absence of capability and nonce checks. This is a foundational security practice that should ideally be present, even in plugins with a minimal attack surface, to ensure robust security against future development or evolving threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

NFCBC SEO Light Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NFCBC SEO Light Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

NFCBC SEO Light Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterget_comment_author_linknfcbc-seo-light.php:108
Maintenance & Trust

NFCBC SEO Light Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJul 12, 2009
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

NFCBC SEO Light Developer Profile

fob

4 plugins · 230 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NFCBC SEO Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
NFCBC SEO Light made by fob marketing (Oliver bockelmann) http://www.fob-marketing.de/ Released under the GPL license+5 more
FAQ

Frequently Asked Questions about NFCBC SEO Light