Schema App Structured Data Security & Risk Analysis

wordpress.org/plugins/schema-app-structured-data-for-schemaorg

Get Schema.org structured data for all pages, posts, categories and profile pages on activation. Use Schema App to customize any Schema Markup.

7K active installs v2.3.0 PHP 5.4+ WP 4.4+ Updated Dec 2, 2025
json-ldrich-snippetsschemaschema-orgstructured-data
97
A · Safe
CVEs total4
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Schema App Structured Data Safe to Use in 2026?

Generally Safe

Score 97/100

Schema App Structured Data has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Dec 11, 2024Updated 4mo ago
Risk Assessment

The static analysis of schema-app-structured-data-for-schemaorg v2.3.0 indicates a strong adherence to secure coding practices within the analyzed code. There are no identified dangerous functions, SQL queries are exclusively handled with prepared statements, and all output is properly escaped. Furthermore, the plugin demonstrates a lack of file operations, external HTTP requests, and demonstrates proper nonce and capability checks, contributing to a reduced attack surface. The absence of any taint analysis findings with unsanitized paths is also a positive indicator.

However, the plugin's vulnerability history presents a significant concern. With four known medium-severity vulnerabilities in its past, including Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Missing Authorization, there is a clear pattern of exploitable weaknesses. While currently none of these appear to be unpatched, the frequency and nature of past vulnerabilities suggest a potential for recurring issues or the discovery of new ones.

In conclusion, while the current version's codebase appears to be well-secured based on static analysis, the historical prevalence of medium-severity vulnerabilities is a notable weakness. Users should remain vigilant and ensure the plugin is updated to the latest version to benefit from any patches applied to address past vulnerabilities. The absence of an immediately apparent attack surface is positive, but the historical context warrants caution.

Key Concerns

  • 4 medium severity vulnerabilities historically
  • Missing capability checks reported historically
  • CSRF vulnerabilities historically
  • XSS vulnerabilities historically
Vulnerabilities
4

Schema App Structured Data Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2024-11279medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Schema App Structured Data <= 2.2.4 - Reflected Cross-Site Scripting

Dec 11, 2024 Patched in 2.2.5 (10d)
CVE-2024-0892medium · 4.3Cross-Site Request Forgery (CSRF)

Schema App Structured Data <= 2.2.0 - Cross-Site Request Forgery

Jun 13, 2024 Patched in 2.2.1 (21d)
CVE-2024-0893medium · 4.3Missing Authorization

Schema App Structured Data <= 2.2.0 - Missing Authorization

May 23, 2024 Patched in 2.2.1 (41d)
CVE-2023-44258medium · 5.3Missing Authorization

Schema App Structured Data <= 1.22.3 - Missing Authorization via page_init

Sep 27, 2023 Patched in 1.22.4 (118d)
Code Analysis
Analyzed Mar 16, 2026

Schema App Structured Data Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Schema App Structured Data Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Schema App Structured Data Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version5.4
Downloads689K

Community Trust

Rating82/100
Number of ratings36
Active installs7K
Developer Profile

Schema App Structured Data Developer Profile

vberkel

1 plugin · 7K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Schema App Structured Data

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/schema-app-structured-data-for-schemaorg/schema-app-structured-data-for-schemaorg.php
Version Parameters
schema-app-structured-data-for-schemaorg/schema-app-structured-data-for-schemaorg.php?ver=2.3.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Schema App Structured Data