Premium Seo Pack – Light Version Security & Risk Analysis

wordpress.org/plugins/premium-seo-pack-light-version

If you want to have better WordPress SEO and a fully optimized WordPress Website then you must use the Premium SEO Pack Plugin!

20 active installs v2.3.1 Lite PHP + WP 5.5+ Updated Aug 20, 2020
mass-optimizationmultiple-focus-keywordspremium-seo-pluginwordpress-seowordpress-seo-plugin
62
C · Use Caution
CVEs total1
Unpatched1
Last CVEMay 1, 2015
Safety Verdict

Is Premium Seo Pack – Light Version Safe to Use in 2026?

Use With Caution

Score 62/100

Premium Seo Pack – Light Version has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: May 1, 2015Updated 5yr ago
Risk Assessment

The "premium-seo-pack-light-version" v2.3.1 Lite plugin exhibits a concerning security posture. While it shows some positive signs like a majority of SQL queries using prepared statements and a reasonable number of output escaping points, these are overshadowed by significant weaknesses. The plugin presents a large attack surface, with 60 out of 69 entry points lacking authentication checks. This is a critical concern, as it allows unauthenticated users to potentially interact with sensitive functionalities. Furthermore, the presence of dangerous functions like `unserialize` and `create_function` combined with a high number of unsanitized taint flows (44 out of 50 analyzed) strongly suggests a high risk of code injection vulnerabilities. The plugin also has a history of a critical, unpatched vulnerability from 2015, specifically related to code injection, which indicates a recurring security issue. The limited number of nonce and capability checks on its numerous entry points further exacerbates these risks.

Key Concerns

  • High number of unprotected AJAX handlers
  • High number of unsanitized taint flows
  • Presence of dangerous functions (unserialize, create_function)
  • Low output escaping percentage
  • Unpatched critical CVE from 2015
  • Low number of nonce checks on entry points
  • Low number of capability checks on entry points
Vulnerabilities
1

Premium Seo Pack – Light Version Security Vulnerabilities

CVEs by Year

1 CVE in 2015 · unpatched
2015
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

WF-b108ba89-56c4-44a8-af61-ccd6f7f73562-premium-seo-pack-light-versioncritical · 9.8Improper Control of Generation of Code ('Code Injection')

AA-Team Premium SEO Pack <= 1.8.0 - Local File Disclosure and Arbitrary File Upload

May 1, 2015Unpatched
Code Analysis
Analyzed Mar 16, 2026

Premium Seo Pack – Light Version Code Analysis

Dangerous Functions
7
Raw SQL Queries
25
84 prepared
Unescaped Output
594
130 escaped
Nonce Checks
3
Capability Checks
3
File Operations
81
External Requests
22
Bundled Libraries
3

Dangerous Functions Found

unserialize$arr = unserialize($serialize);aa-framework\ajax-list-table.php:1722
unserialize$return[$value['option_name']] = @unserialize($value['option_value']);aa-framework\framework.class.php:1473
unserialize$db_postTo = unserialize($db_postTo);modules\facebook_planner\app.cron.class.php:97
create_functionadd_filter('wp_mail_content_type', create_function('', 'return "text/html";'));modules\facebook_planner\app.cron.class.php:255
unserialize$whereToPost = unserialize($whereToPost);modules\facebook_planner\app.fb-utils.class.php:175
unserialize$post_to_check = unserialize( $this->fb_schedule_value('post_to', $post_id) );modules\facebook_planner\init.php:411
unserialize$getdata = unserialize( $getdata );modules\sitemap\video_info.php:120

Bundled Libraries

Select2TinyMCEGuzzle

SQL Query Safety

77% prepared109 total queries

Output Escaping

18% escaped724 total outputs
Data Flows
44 unsanitized

Data Flow Analysis

25 flows44 with unsanitized paths
get_remote_website_content (modules\Backlink_Builder\init.php:562)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
60 unprotected

Premium Seo Pack – Light Version Attack Surface

Entry Points69
Unprotected60

AJAX Handlers 62

authwp_ajax_pspAjaxListaa-framework\ajax-list-table.php:67
authwp_ajax_pspAjaxList_actionsaa-framework\ajax-list-table.php:68
authwp_ajax_PSP_framework_styleaa-framework\framework.class.php:151
noprivwp_ajax_PSP_framework_styleaa-framework\framework.class.php:152
authwp_ajax_pspLoadSectionaa-framework\framework.class.php:282
authwp_ajax_pspSaveOptionsaa-framework\framework.class.php:315
authwp_ajax_pspModuleChangeStatusaa-framework\framework.class.php:318
authwp_ajax_pspModuleChangeStatus_bulk_rowsaa-framework\framework.class.php:321
authwp_ajax_pspInstallDefaultOptionsaa-framework\framework.class.php:324
authwp_ajax_pspW3CValidateaa-framework\framework.class.php:327
authwp_ajax_pspUploadaa-framework\framework.class.php:330
authwp_ajax_pspWPMediaUploadImageaa-framework\framework.class.php:331
authwp_ajax_pspDismissNoticeaa-framework\framework.class.php:332
authwp_ajax_pspAdminAjaxaa-framework\utils\action_admin_ajax.php:33
authwp_ajax_pspMinifyAdminCacheaa-framework\utils\action_admin_ajax.php:36
authwp_ajax_pspMinifyAdminExcludingaa-framework\utils\action_admin_ajax.php:37
authwp_ajax_pspVideoMetasaa-framework\utils\action_admin_ajax.php:40
authwp_ajax_psp_cronjobsaa-framework\utils\action_admin_ajax.php:43
authwp_ajax_pspSocialSharingaa-framework\utils\action_admin_ajax.php:45
authwp_ajax_pspTwitterCardsaa-framework\utils\action_admin_ajax.php:46
authwp_ajax_pspSocialSharingFrontendaa-framework\utils\action_admin_ajax.php:48
noprivwp_ajax_pspSocialSharingFrontendaa-framework\utils\action_admin_ajax.php:49
authwp_ajax_pspimportSEODataaa-framework\utils\import_seodata.php:30
authwp_ajax_pspPageBuilderRequestmodules\Backlink_Builder\init.php:45
authwp_ajax_pspCapabilities_changeUsermodules\capabilities\init.php:69
authwp_ajax_pspCapabilities_saveChangesmodules\capabilities\init.php:70
authwp_ajax_pspDashboardRequestmodules\dashboard\ajax.php:23
authwp_ajax_pspDashboardRequestmodules\depedencies\ajax.php:23
authwp_ajax_psp_facebookAuthmodules\facebook_planner\init.php:76
authwp_ajax_psp_publish_fb_nowmodules\facebook_planner\init.php:83
authwp_ajax_psp_metabox_fbmodules\facebook_planner\init.php:113
authwp_ajax_pspFileEditmodules\file_edit\init.php:48
authwp_ajax_pspGoogleAuthorizeAppmodules\Google_Analytics\init.php:57
authwp_ajax_pspGoogleAPIRequestmodules\Google_Analytics\init.php:58
authwp_ajax_pspPageSpeedInsightsRequestmodules\google_pagespeed\ajax.php:29
authwp_ajax_pspGetUpdateDataBuildermodules\Link_Builder\init.php:54
authwp_ajax_pspAddToBuildermodules\Link_Builder\init.php:55
authwp_ajax_pspUpdateToBuildermodules\Link_Builder\init.php:56
authwp_ajax_pspGetHitsByPhrasemodules\Link_Builder\init.php:57
authwp_ajax_pspGetUpdateDataRedirectmodules\Link_Redirect\init.php:53
authwp_ajax_pspAddToRedirectmodules\Link_Redirect\init.php:54
authwp_ajax_pspUpdateToRedirectmodules\Link_Redirect\init.php:55
authwp_ajax_inline-save-taxmodules\Link_Redirect\init.php:117
authwp_ajax_psp_metabox_localseomodules\local_seo\init.php:62
authwp_ajax_pspGet404MonitorRequestmodules\monitor_404\init.php:41
authwp_ajax_psp404MonitorToRedirectmodules\monitor_404\init.php:42
authwp_ajax_pspOptimizePagemodules\on_page_optimization\init.php:48
authwp_ajax_pspGetSeoReportmodules\on_page_optimization\init.php:49
authwp_ajax_pspQuickEditmodules\on_page_optimization\init.php:50
authwp_ajax_psp_metabox_seosettingsmodules\on_page_optimization\init.php:53
authwp_ajax_pspAddToReportermodules\serp\init.php:57
authwp_ajax_pspUpdateToReportermodules\serp\init.php:58
authwp_ajax_pspRemoveFromReportermodules\serp\init.php:59
authwp_ajax_pspGetSERPGraphDatamodules\serp\init.php:61
authwp_ajax_pspSetSearchEnginemodules\serp\init.php:62
authwp_ajax_pspGetEngineAccessTimemodules\serp\init.php:64
authwp_ajax_pspGetFocusKWmodules\serp\init.php:65
authwp_ajax_pspServerStatusRequestmodules\server_status\ajax.php:25
authwp_ajax_pspServerStatusVerifymodules\server_status\ajax.php:26
authwp_ajax_pspServerStatusOperationmodules\server_status\ajax.php:27
authwp_ajax_psp_tiny_compressmodules\tiny_compress\init.php:97
authwp_ajax_pspHtmlValidatemodules\W3C_HTMLValidator\init.php:43

Shortcodes 7

[psp_business] modules\local_seo\sitemap_and_shortcodes.php:714
[psp_address] modules\local_seo\sitemap_and_shortcodes.php:715
[psp_contact] modules\local_seo\sitemap_and_shortcodes.php:716
[psp_opening_hours] modules\local_seo\sitemap_and_shortcodes.php:717
[psp_payment] modules\local_seo\sitemap_and_shortcodes.php:718
[psp_gmap] modules\local_seo\sitemap_and_shortcodes.php:719
[psp_full] modules\local_seo\sitemap_and_shortcodes.php:720
WordPress Hooks 126
filterposts_whereaa-framework\ajax-list-table.php:403
filterposts_whereaa-framework\ajax-list-table.php:665
actionadmin_initaa-framework\framework.class.php:291
actionadmin_initaa-framework\framework.class.php:299
actioninitaa-framework\framework.class.php:302
actioninitaa-framework\framework.class.php:309
actioninitaa-framework\framework.class.php:310
actionadmin_initaa-framework\framework.class.php:359
actionwp_footeraa-framework\framework.class.php:362
actionadmin_footeraa-framework\framework.class.php:363
filterthe_contentaa-framework\framework.class.php:401
filterterm_descriptionaa-framework\framework.class.php:403
filterterm_descriptionaa-framework\framework.class.php:404
actionwpaa-framework\framework.class.php:406
actionadmin_print_stylesaa-framework\framework.class.php:412
actionadmin_noticesaa-framework\framework.class.php:683
actionadmin_print_stylesaa-framework\framework.class.php:778
actionadmin_print_scriptsaa-framework\framework.class.php:779
actionadmin_noticesaa-framework\framework.class.php:782
actionadmin_noticesaa-framework\framework.class.php:785
actionadmin_menuaa-framework\framework.class.php:789
actionadmin_noticesaa-framework\framework.class.php:2702
actionadmin_noticesaa-framework\framework.class.php:2994
actionadmin_initaa-framework\shortcodes\shortcodes.init.php:38
actioninitaa-framework\shortcodes\shortcodes.init.php:40
filtermce_external_pluginsaa-framework\shortcodes\shortcodes.init.php:53
filtermce_buttonsaa-framework\shortcodes\shortcodes.init.php:54
actionwp_enqueue_scriptsaa-framework\utils\social_sharing.php:66
actionwp_enqueue_scriptsaa-framework\utils\social_sharing.php:67
actionwp_headaa-framework\utils\social_sharing.php:69
actionwp_footeraa-framework\utils\social_sharing.php:70
filterthe_contentaa-framework\utils\social_sharing.php:95
actionadmin_menumodules\Backlink_Builder\init.php:40
actionadmin_menumodules\capabilities\init.php:64
filtercron_schedulesmodules\cronjobs\cronjobs.core.php:81
actioninitmodules\cronjobs\cronjobs.core.php:83
actionadmin_print_scriptsmodules\dashboard\init.php:43
actionadmin_enqueue_scriptsmodules\depedencies\init.php:43
actionadmin_print_scriptsmodules\depedencies\init.php:44
filterwp_mail_content_typemodules\facebook_planner\app.cron.class.php:255
actionadmin_menumodules\facebook_planner\init.php:47
actionsave_postmodules\facebook_planner\init.php:87
actionadmin_menumodules\file_edit\init.php:41
actionwp_headmodules\frontend\init.php:51
actionwp_footermodules\frontend\init.php:54
actiondo_robotsmodules\frontend\init.php:57
actionpremiumseo_headmodules\Google_Analytics\init.php:43
actionadmin_menumodules\Google_Analytics\init.php:54
actionpsp_google_analytics_get_profilesmodules\Google_Analytics\init.php:60
actioninitmodules\Google_Analytics\init.php:64
actionpremiumseo_headmodules\google_authorship\init.php:91
actionpremiumseo_footermodules\google_authorship\init.php:92
actionadmin_menumodules\google_pagespeed\init.php:38
actionadmin_menumodules\Link_Builder\init.php:51
filterthe_contentmodules\Link_Builder\init.php:68
filtercomment_textmodules\Link_Builder\init.php:71
actionadmin_menumodules\Link_Redirect\init.php:50
actionwpmodules\Link_Redirect\init.php:66
actionadmin_initmodules\Link_Redirect\init.php:71
actionedit_form_advancedmodules\Link_Redirect\init.php:96
actionedit_page_formmodules\Link_Redirect\init.php:97
actionpost_updatedmodules\Link_Redirect\init.php:100
actionedited_termmodules\Link_Redirect\init.php:120
actionadmin_headmodules\local_seo\init.php:102
actionadmin_menumodules\local_seo\init.php:105
actionsave_postmodules\local_seo\init.php:108
actionadmin_headmodules\local_seo\init.php:111
actionadmin_initmodules\local_seo\init.php:1072
actioninitmodules\local_seo\sitemap_and_shortcodes.php:57
actionwp_print_scriptsmodules\Minify\init.php:101
actionwp_print_stylesmodules\Minify\init.php:108
filtername_save_premodules\misc\init.php:66
filtersanitize_titlemodules\misc\init.php:71
actionpremiumseo_headmodules\misc\init.php:146
actionwp_footermodules\misc\init.php:147
actionadmin_menumodules\monitor_404\init.php:38
actiontemplate_redirectmodules\monitor_404\init.php:51
actionadmin_menumodules\on_page_optimization\init.php:39
actionsave_postmodules\on_page_optimization\init.php:42
actionadmin_footermodules\on_page_optimization\init.php:45
actionrestrict_manage_postsmodules\on_page_optimization\init.php:77
filterrequestmodules\on_page_optimization\init.php:78
actionadmin_initmodules\on_page_optimization\init.php:2430
actionedit_termmodules\on_page_optimization\init.php:2450
filterthe_contentmodules\seo_friendly_images\init.php:54
filterpost_thumbnail_htmlmodules\seo_friendly_images\init.php:58
actionadmin_menumodules\serp\init.php:54
actionwp_headmodules\serp\init.php:73
filterwp_mail_content_typemodules\serp\init.php:1433
actionadmin_menumodules\server_status\init.php:39
actionafter_setup_thememodules\sitemap\init.php:123
filterthe_contentmodules\sitemap\init.php:124
actionpremiumseo_opengraphmodules\sitemap\init.php:128
filterpremiumseo_opengraph_typemodules\sitemap\init.php:129
filterpremiumseo_opengraph_titlemodules\sitemap\init.php:130
filterpremiumseo_opengraph_descriptionmodules\sitemap\init.php:131
filterpremiumseo_opengraph_imagemodules\sitemap\init.php:132
actionadmin_menumodules\Social_Stats\init.php:41
actionadmin_menumodules\tiny_compress\init.php:77
filterwp_generate_attachment_metadatamodules\tiny_compress\init.php:91
filterpremiumseo_seo_settingsmodules\title_meta_format\buddypress.init.php:58
filterpremiumseo_seo_pagetypemodules\title_meta_format\buddypress.init.php:59
filterpremiumseo_seo_list_pagetypesmodules\title_meta_format\buddypress.init.php:60
filterpremiumseo_seo_make_formatmodules\title_meta_format\buddypress.init.php:61
filterpremiumseo_seo_titlemodules\title_meta_format\buddypress.init.php:64
filterpremiumseo_seo_meta_descriptionmodules\title_meta_format\buddypress.init.php:65
filterpremiumseo_seo_meta_keywordsmodules\title_meta_format\buddypress.init.php:66
filterpremiumseo_seo_robotsmodules\title_meta_format\buddypress.init.php:67
filterpremiumseo_seo_list_pagetypesmodules\title_meta_format\init.php:64
filterpremiumseo_seo_pagetypemodules\title_meta_format\init.php:65
actionpremiumseo_headmodules\title_meta_format\init.php:153
actionpremiumseo_headmodules\title_meta_format\init.php:154
actionpremiumseo_headmodules\title_meta_format\init.php:155
actionpremiumseo_headmodules\title_meta_format\init.php:156
actiontemplate_redirectmodules\title_meta_format\init.php:163
actionwp_headmodules\title_meta_format\init.php:164
filterwp_titlemodules\title_meta_format\init.php:166
filterlanguage_attributesmodules\title_meta_format\init.social.php:86
actionpremiumseo_opengraphmodules\title_meta_format\init.social.php:87
actionpremiumseo_opengraphmodules\title_meta_format\init.social.php:88
actionpremiumseo_headmodules\title_meta_format\init.social.php:90
actionpremiumseo_twitter_cardsmodules\title_meta_format\init.social.twitter_cards.php:54
actionpremiumseo_headmodules\title_meta_format\init.social.twitter_cards.php:56
actionadmin_menumodules\W3C_HTMLValidator\init.php:38
actionplugins_loadedplugin.php:28
actionplugins_loadedplugin.php:29
Maintenance & Trust

Premium Seo Pack – Light Version Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 20, 2020
PHP min version
Downloads15K

Community Trust

Rating20/100
Number of ratings3
Active installs20
Developer Profile

Premium Seo Pack – Light Version Developer Profile

AA-Team

3 plugins · 70 total installs

78
trust score
Avg Security Score
77/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Premium Seo Pack – Light Version

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/premium-seo-pack-light-version/css/frontend.css/wp-content/plugins/premium-seo-pack-light-version/css/style.css/wp-content/plugins/premium-seo-pack-light-version/js/main.js/wp-content/plugins/premium-seo-pack-light-version/js/frontend.js/wp-content/plugins/premium-seo-pack-light-version/aa-framework/css/min.css/wp-content/plugins/premium-seo-pack-light-version/aa-framework/css/style.css/wp-content/plugins/premium-seo-pack-light-version/aa-framework/js/main.js
Script Paths
/wp-content/plugins/premium-seo-pack-light-version/aa-framework/js/main.js/wp-content/plugins/premium-seo-pack-light-version/js/main.js/wp-content/plugins/premium-seo-pack-light-version/js/frontend.js/wp-content/plugins/premium-seo-pack-light-version/aa-framework/css/min.css
Version Parameters
premium-seo-pack-light-version/css/frontend.css?ver=premium-seo-pack-light-version/css/style.css?ver=premium-seo-pack-light-version/js/main.js?ver=premium-seo-pack-light-version/js/frontend.js?ver=premium-seo-pack-light-version/aa-framework/css/min.css?ver=premium-seo-pack-light-version/aa-framework/css/style.css?ver=premium-seo-pack-light-version/aa-framework/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
psp-title-wrapperpsp-shortcodes-wrapper
HTML Comments
<!-- AA-Team -->
Data Attributes
data-plugin-namedata-plugin-versiondata-plugin-author
JS Globals
psp_ajax_urlpsp_site_urlaa_framework_url
Shortcode Output
[psp_admin_links][psp_admin_buttons][psp_admin_shortcode][psp_meta_title]
FAQ

Frequently Asked Questions about Premium Seo Pack – Light Version