
Opti Marketing Security & Risk Analysis
wordpress.org/plugins/opti-marketingO primeiro plugin de SEO e GEO com geração de conteúdo por inteligência artificial
Is Opti Marketing Safe to Use in 2026?
Generally Safe
Score 97/100Opti Marketing has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The opti-marketing v3.0.51 plugin exhibits a concerning security posture due to a substantial attack surface with a high proportion of unprotected entry points. Out of 69 identified entry points, 62 lack explicit authentication checks, primarily consisting of AJAX handlers. While the code demonstrates good practices in SQL query sanitization (100% prepared statements) and output escaping (100% properly escaped), the lack of authentication on a vast majority of its handlers significantly increases the risk of unauthorized actions if any of these handlers have exploitable logic. The presence of a past critical SQL injection vulnerability, although currently patched, is a significant red flag. This history, coupled with the large number of unprotected AJAX endpoints, suggests a potential for attackers to discover and exploit vulnerabilities in these handlers if they contain flaws, even if current static analysis doesn't reveal obvious taint flows. The plugin's overall strength lies in its secure handling of SQL and output, but this is heavily undermined by the vast unprotected attack surface and past critical vulnerability.
Key Concerns
- Large attack surface without authentication
- Critical vulnerability in history
- REST API route without permission callback
- Only one nonce check for 66 AJAX handlers
- Only 16 capability checks for 66 AJAX handlers
Opti Marketing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Opti Marketing <= 2.0.9 - Unauthenticated SQL Injection
Opti Marketing Release Timeline
Opti Marketing Code Analysis
SQL Query Safety
Output Escaping
Opti Marketing Attack Surface
AJAX Handlers 66
REST API Routes 3
WordPress Hooks 36
Maintenance & Trust
Opti Marketing Maintenance & Trust
Maintenance Signals
Community Trust
Opti Marketing Alternatives
No alternatives data available yet.
Opti Marketing Developer Profile
1 plugin · 10 total installs
How We Detect Opti Marketing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/opti-marketing/js/activation_modal.js/wp-content/plugins/opti-marketing/assets/css/style.css/wp-content/plugins/opti-marketing/assets/js/script.js/wp-content/plugins/opti-marketing/assets/js/app.js/wp-content/plugins/opti-marketing/js/activation_modal.js/wp-content/plugins/opti-marketing/assets/js/script.js/wp-content/plugins/opti-marketing/assets/js/app.jsopti-marketing/js/activation_modal.js?ver=opti-marketing/assets/css/style.css?ver=opti-marketing/assets/js/script.js?ver=opti-marketing/assets/js/app.js?ver=HTML / DOM Fingerprints
sitemap-radiositemap-textsitemap-save-btndata-opti-marketingOPTIMARKET_API_URLOPTI_API_KEYopti_log_debugopti_marketing_ajax_object/wp-json/opti-marketing/v1/data[opti_marketing_display_ranking][opti_marketing_article_analysis]