
PageOne Security & Risk Analysis
wordpress.org/plugins/pageonePageOne is a platform for creating blog posts, images, meta descriptions, and focus key phrases. PageOne also offers keyword research.
Is PageOne Safe to Use in 2026?
Generally Safe
Score 92/100PageOne has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pageone" plugin v3.1.2 presents a significant security risk primarily due to its extensive unprotected attack surface. All 18 identified AJAX handlers lack authentication checks, meaning any unauthenticated user can trigger these actions. This is a critical oversight that could allow for unauthorized data manipulation or unintended system behavior. Additionally, the complete absence of nonce checks on these AJAX handlers further exacerbates the risk of cross-site request forgery (CSRF) attacks.
While the plugin demonstrates strengths in other areas, such as the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output, these positive aspects are overshadowed by the severe lack of authorization and authentication on its AJAX endpoints. The taint analysis, despite showing no critical or high-severity unsanitized flows, does not mitigate the fundamental risk posed by unprotected entry points. The plugin's clean vulnerability history is a positive sign, suggesting good development practices in the past, but it cannot compensate for the current exposure. The presence of `ini_set` calls, while not inherently a vulnerability, warrants careful review in the context of an otherwise unprotected AJAX interface as it could be used for malicious configuration changes.
In conclusion, the "pageone" plugin v3.1.2 has a weak security posture due to a large, unprotected attack surface. The lack of authentication and nonce checks on all AJAX handlers represents a critical vulnerability. While other code quality indicators are positive, they do not offset this fundamental flaw. Users should exercise extreme caution and consider alternative plugins or implementing custom security measures if continued use of this plugin is necessary.
Key Concerns
- 18 unprotected AJAX handlers
- 0 Nonce checks on AJAX handlers
- 0 Capability checks on AJAX handlers
- 10 Dangerous functions (ini_set)
- 10 Flows with unsanitized paths
PageOne Security Vulnerabilities
PageOne Release Timeline
PageOne Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
PageOne Attack Surface
AJAX Handlers 18
WordPress Hooks 11
Maintenance & Trust
PageOne Maintenance & Trust
Maintenance Signals
Community Trust
PageOne Alternatives
Auto Ping Booster
auto-ping-booster
Auto Ping Booster will auto ping your blog in Google, Baidu, Yandex and many search engines after each update.
Accounting Records Copywriter
accounting-records-copywriter
Упрощение работы администратора с копиратером рерайтером на вашем блоге / Admin’s work simplification with copywriter rewriter for your blog
NextBrill Autopost
nextbrill-autopost
AI-powered WordPress plugin that generates and publishes SEO-optimized blog posts using OpenAI. Add one post at a time, process it, then add the next.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
WP All Import – Import SEO Settings for Yoast SEO
yoast-seo-settings-xml-csv-import
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into Yoast SEO's titles, meta descriptions, focus keywords, schema sett …
PageOne Developer Profile
1 plugin · 10 total installs
How We Detect PageOne
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pageone/pageone-styles.cssHTML / DOM Fingerprints
content-containercontentheadermain-titlekeywords-countercounter-numbercounter-textsub-header+35 moreHeader section with title and counterMain content area with formForm sectionProgress bar section+3 moreid="seo-ai-keyword-count"id="seo-ai-search-area"id="seo-ai-keywords"id="seo_ai_daily_limit"id="seo-ai-post-btn"id="seo-ai-meter-wrap"+9 moreseoApiSendseoAiDeleteKeywordseo_ai_accountInfoseo_ai__options