
Semrush SEO Writing Assistant Security & Risk Analysis
wordpress.org/plugins/semrush-seo-writing-assistantThe Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Is Semrush SEO Writing Assistant Safe to Use in 2026?
Generally Safe
Score 100/100Semrush SEO Writing Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The semrush-seo-writing-assistant plugin v1.2.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface vectors, dangerous functions, raw SQL queries, unescaped output, or file operations is highly commendable. The taint analysis showing zero flows with unsanitized paths further reinforces this positive assessment. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a consistent track record of security.
However, the static analysis also reveals a complete absence of capability checks and nonce checks. While the current lack of an attack surface might mitigate immediate risks, this omission represents a significant potential weakness. If new functionalities are introduced that create entry points, they may not be adequately protected against unauthorized access or cross-site request forgery. The plugin's strengths lie in its clean code and lack of known vulnerabilities, but the reliance on an inert attack surface for security is a concerning, albeit currently unexploited, vulnerability.
In conclusion, the plugin is currently very secure due to a lack of exploitable features and a clean history. The primary concern is the missing capability and nonce checks, which, while not an immediate threat, represent a critical oversight for future development and a potential vulnerability if the attack surface expands.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Semrush SEO Writing Assistant Security Vulnerabilities
Semrush SEO Writing Assistant Code Analysis
Output Escaping
Semrush SEO Writing Assistant Attack Surface
WordPress Hooks 2
Maintenance & Trust
Semrush SEO Writing Assistant Maintenance & Trust
Maintenance Signals
Community Trust
Semrush SEO Writing Assistant Alternatives
SEO Writing Assistant SEMrush Custom Fields
seo-writing-assistant-semrush-custom-fields
The SEMrush SEO Writing Assistant plugin read only from post title and post content elements for the real time check.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Topic SEO Content Optimization Tool
topic
Find and fix topical gaps in your SEO Content. Rank higher on search.
Textmetrics
webtexttool
Textmetrics is the easiest way to create SEO proof content to rank higher and get more traffic. Realtime optimization, keyword research and more.
Semrush SEO Writing Assistant Developer Profile
2 plugins · 12K total installs
How We Detect Semrush SEO Writing Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/semrush-seo-writing-assistant/admin/class-semrushswa-metabox.php//www.semrush.com/swa/addon/nocache/js/wordpress.jssemrush-seo-writing-assistantHTML / DOM Fingerprints
swa-containerdata-swa-docurldata-swa-docid