
S-DEV SEO Security & Risk Analysis
wordpress.org/plugins/s-dev-seoSEO Tool which replace titles on selected pages and posts. Also adds ability for meta description.
Is S-DEV SEO Safe to Use in 2026?
Mostly Safe
Score 79/100S-DEV SEO is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin 's-dev-seo' v1.88 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and including nonce and capability checks, indicating an effort to implement basic security controls. File operations and external HTTP requests are also absent, which reduces potential attack vectors.
However, significant concerns arise from the output escaping, where only 22% of outputs are properly escaped. This low percentage suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as untrusted input could be directly rendered in the browser without adequate sanitization. The vulnerability history confirms this, with one known medium severity CVE attributed to XSS, and this vulnerability is currently unpatched. The fact that the last vulnerability was dated in the future (2025-01-14) is a data anomaly that should be investigated, but it doesn't negate the existing XSS risk.
In conclusion, while 's-dev-seo' v1.88 has a limited attack surface and uses prepared statements, the pervasive issue of unescaped output and the presence of an unpatched XSS vulnerability represent critical risks. The plugin needs immediate attention to address the output escaping flaws and to patch the known CVE.
Key Concerns
- Unpatched CVE (Medium Severity XSS)
- Low percentage of properly escaped output
S-DEV SEO Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
S-DEV SEO <= 1.88 - Authenticated (Contributor+) Stored Cross-Site Scripting
S-DEV SEO Code Analysis
Output Escaping
S-DEV SEO Attack Surface
WordPress Hooks 14
Maintenance & Trust
S-DEV SEO Maintenance & Trust
Maintenance Signals
Community Trust
S-DEV SEO Alternatives
Bulk Meta Tags Updater
bulk-meta-tags-updater
Efficiently update meta titles and descriptions in bulk for WordPress posts and pages.
WP Simple SEO Meta
wp-simple-seo-meta
Add page title, meta description, keywords and robots to all post types and taxonomies.
WP Smart SEO
wp-smart-seo
Improve your WordPress SEO: Enter your title, description and featured image for better visibility in the search engine
Bulk Interlinking Tool
bulk-interlinking-tool
Effortlessly convert keywords to hyperlinks with Bulk Interlinking Tool for WordPress, plus optimize titles and meta descriptions for better SEO.
SkySEOManager | Bult Edit SEO Title, Description, Alt text Using AI
sky-seo-manager
A powerful SEO plugin for bulk editing meta titles, descriptions, and featured images, with AI-powered media optimization and SEO plugin integration.
S-DEV SEO Developer Profile
1 plugin · 50 total installs
How We Detect S-DEV SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/s-dev-seo/css/sdev-seo.css/wp-content/plugins/s-dev-seo/js/sdev-seo.js/wp-content/plugins/s-dev-seo/js/sdev-seo.jss-dev-seo/css/sdev-seo.css?ver=s-dev-seo/js/sdev-seo.js?ver=HTML / DOM Fingerprints
<!-- S-DEV SEO --><!-- /S-DEV SEO -->