Semrush SEO Writing Assistant Security & Risk Analysis

wordpress.org/plugins/semrush-seo-writing-assistant

The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.

10K active installs v1.2.1 PHP 5.2.4+ WP 4.8+ Updated Dec 22, 2025
content-analysiscontent-marketingreadabilityseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Semrush SEO Writing Assistant Safe to Use in 2026?

Generally Safe

Score 100/100

Semrush SEO Writing Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The semrush-seo-writing-assistant plugin v1.2.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface vectors, dangerous functions, raw SQL queries, unescaped output, or file operations is highly commendable. The taint analysis showing zero flows with unsanitized paths further reinforces this positive assessment. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a consistent track record of security.

However, the static analysis also reveals a complete absence of capability checks and nonce checks. While the current lack of an attack surface might mitigate immediate risks, this omission represents a significant potential weakness. If new functionalities are introduced that create entry points, they may not be adequately protected against unauthorized access or cross-site request forgery. The plugin's strengths lie in its clean code and lack of known vulnerabilities, but the reliance on an inert attack surface for security is a concerning, albeit currently unexploited, vulnerability.

In conclusion, the plugin is currently very secure due to a lack of exploitable features and a clean history. The primary concern is the missing capability and nonce checks, which, while not an immediate threat, represent a critical oversight for future development and a potential vulnerability if the attack surface expands.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

Semrush SEO Writing Assistant Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Semrush SEO Writing Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Semrush SEO Writing Assistant Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadd_meta_boxesadmin\class-semrushswa-metabox.php:32
actionplugins_loadedsemrush-seo-writing-assistant.php:60
Maintenance & Trust

Semrush SEO Writing Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version5.2.4
Downloads172K

Community Trust

Rating56/100
Number of ratings25
Active installs10K
Developer Profile

Semrush SEO Writing Assistant Developer Profile

SEMrush CY LTD

2 plugins · 12K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
32 days
View full developer profile
Detection Fingerprints

How We Detect Semrush SEO Writing Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/semrush-seo-writing-assistant/admin/class-semrushswa-metabox.php
Script Paths
//www.semrush.com/swa/addon/nocache/js/wordpress.js
Version Parameters
semrush-seo-writing-assistant

HTML / DOM Fingerprints

CSS Classes
swa-container
Data Attributes
data-swa-docurldata-swa-docid
FAQ

Frequently Asked Questions about Semrush SEO Writing Assistant