
Post To SEO Security & Risk Analysis
wordpress.org/plugins/post-to-seoHelps generating the main SEO components Keywords, 160 char description and tags.
Is Post To SEO Safe to Use in 2026?
Generally Safe
Score 85/100Post To SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-to-seo" v1.0 plugin exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and shows no recorded vulnerability history or critical taint flows, its static analysis reveals major weaknesses. The presence of an unprotected AJAX handler represents a substantial attack vector. Furthermore, the complete absence of output escaping across all identified outputs is a critical flaw that could easily lead to cross-site scripting (XSS) vulnerabilities. The lack of nonce and capability checks on its entry points further exacerbates these risks. In conclusion, despite its clean vulnerability history and secure SQL practices, the "post-to-seo" plugin has critical security deficiencies related to input validation and output sanitization that demand immediate attention.
Key Concerns
- Unprotected AJAX handler
- No output escaping
- No nonce checks
- No capability checks
Post To SEO Security Vulnerabilities
Post To SEO Release Timeline
Post To SEO Code Analysis
Output Escaping
Post To SEO Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Post To SEO Maintenance & Trust
Maintenance Signals
Community Trust
Post To SEO Alternatives
Automatic Post Tagger
automatic-post-tagger
Adds relevant taxonomy terms to posts using a keyword list provided by the user.
FV Simpler SEO
fv-all-in-one-seo-pack
Simple and effective SEO. Non-invasive, elegant. Ideal for client facing projects.
Post SEO Score Checker
post-seo-score-checker
Post SEO Score Checker plugin checks your Post SEO before it's Published and helps to improve your Website SEO (Search Engine Optimization).
HeadMeta
headmeta
Automatically add <link>, <meta> description and <meta> keywords to your HTML on a per-post (or page) basis.
Post Filter
post-filter
Prevent from publishing posts with unwanted content/words Delete posts on your WordPress blog by keyword immediately after published
Post To SEO Developer Profile
4 plugins · 40 total installs
How We Detect Post To SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-to-seo/css/style.css/wp-content/plugins/post-to-seo/js/post-to-seo.js/wp-content/plugins/post-to-seo/js/post-to-seo.jspost-to-seo/css/style.css?ver=post-to-seo/js/post-to-seo.js?ver=HTML / DOM Fingerprints
data-thPostToSEO/wp-json/post-to-seo/v1/generate