
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Security & Risk Analysis
wordpress.org/plugins/review-schemaAI-Powered schema markup plugin for WordPress. Generate JSON-LD schema and FAQs, validate Rich Results, and audit your structured data.
Is Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Safe to Use in 2026?
Generally Safe
Score 95/100Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'review-schema' plugin v2.2.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices such as 100% of SQL queries using prepared statements and a high rate of output escaping (93%). The presence of 27 nonce checks and 15 capability checks also suggests an effort to secure its functionalities. However, significant concerns arise from its attack surface. With 26 total entry points, 4 of which lack authentication checks, there is a direct pathway for unauthenticated users to interact with potentially sensitive plugin functions. This is further exacerbated by the presence of 18 dangerous function calls, notably 'unserialize', which can be a vector for various exploits if not handled with extreme care and input validation.
Taint analysis indicates no critical or high severity unsanitized paths, which is a positive sign. However, the single flow with an unsanitized path, while not flagged as critical or high, still represents a potential risk that should be addressed. The plugin's vulnerability history is a significant concern. Having 2 known CVEs, including one high and one medium severity vulnerability, indicates a pattern of past security weaknesses. The common vulnerability types found (PHP Remote File Inclusion and Missing Authorization) align with the static analysis findings of unprotected AJAX handlers and the use of 'unserialize'. The fact that the last vulnerability was in early 2025 is also noteworthy, suggesting a recent history of security issues. While there are currently no unpatched vulnerabilities, the historical pattern necessitates vigilance.
In conclusion, while the plugin employs some strong security measures like prepared statements and output escaping, the substantial number of unprotected AJAX handlers and the presence of 'unserialize' combined with a history of significant vulnerabilities represent considerable risks. The plugin needs further hardening to address the unauthenticated entry points and ensure robust sanitization around deserialization operations to improve its overall security. The past vulnerability history suggests a recurring need for thorough security reviews and patching.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function 'unserialize' detected
- Flow with unsanitized path detected
- High severity CVE in history
- Medium severity CVE in history
- Common vulnerability type: Missing Authorization
- Common vulnerability type: PHP Remote File Inclusion
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Review Schema – Review & Structure Data Schema Plugin <= 2.2.6 - Authenticated (Subscriber+) Information Exposure
Review Schema <= 2.2.4 - Authenticated (Contributor+) Local File Inclusion via Post Meta
WordPress Review & Structure Data Schema Plugin – Review Schema <= 2.1.14 - Missing Authorization to Arbitrary Review Update
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Release Timeline
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Attack Surface
AJAX Handlers 26
WordPress Hooks 73
Maintenance & Trust
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Maintenance & Trust
Maintenance Signals
Community Trust
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Alternatives
Schema & Structured Data for WP & AMP
schema-and-structured-data-for-wp
Schema & Structured Data adds Google Rich Snippets markup according to Schema.org guidelines to structure your site for SEO.
Schema – All In One Schema Rich Snippets
all-in-one-schemaorg-rich-snippets
Improve SEO, elevate rankings and Boost CTR. Supports different types of content and works well with Google, Bing, Yahoo, and Facebook.
WP SEO Structured Data Schema
wp-seo-structured-data-schema
Comprehensive JSON-LD based Structured Data solution for WordPress for adding schema for organizations, businesses, blog posts, ratings & more.
FAQ Schema Markup – FAQ Structured Data
faq-schema-markup-faq-structured-data
Schema FAQ - Super fast, light-weight plugin to add FAQ Schema structured data markup in recommended JSON-LD format automatically to WordPress sites.
Schema Scalpel
schema-scalpel
Add custom JSON-LD schema markup per post or page with a powerful new editor metabox – precise, fast, and SEO-boosting.
Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO Developer Profile
16 plugins · 213K total installs
How We Detect Schema Engine AI – AI Schema Markup, Reviews & Rich Snippets for SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-schema/assets/css/review-schema-public.css/wp-content/plugins/review-schema/assets/css/review-schema-admin.css/wp-content/plugins/review-schema/assets/js/review-schema-public.js/wp-content/plugins/review-schema/assets/js/review-schema-admin.jsreview-schema/assets/css/review-schema-public.css?ver=review-schema/assets/css/review-schema-admin.css?ver=review-schema/assets/js/review-schema-public.js?ver=review-schema/assets/js/review-schema-admin.js?ver=HTML / DOM Fingerprints
review-schema-rating-wrapperreview-schema-titlereview-schema-descriptionreview-schema-author-inforeview-schema-datedata-rtrs-rating-valuedata-rtrs-schema-typertrs_public_paramsrtrs_admin_params[review_schema rating_value='[review_schema_form]