Sentence To SEO (keywords, description and tags) Security & Risk Analysis

wordpress.org/plugins/sentence-to-seo

This plugin converts any plain text into the main SEO components, 160 chars description, keywords and Tags

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jul 10, 2015
sentence-to-seoseoseo-helpertext-to-seo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 21, 2026
Download
Safety Verdict

Is Sentence To SEO (keywords, description and tags) Safe to Use in 2026?

Use With Caution

Score 63/100

Sentence To SEO (keywords, description and tags) has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 21, 2026Updated 10yr ago
Risk Assessment

The "sentence-to-seo" plugin, version 1.0, presents a generally positive initial security posture, primarily due to the absence of detected vulnerabilities in its history and a seemingly limited attack surface based on the provided static analysis. The code signals indicate a strong adherence to secure coding practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, the lack of file operations and external HTTP requests suggests a contained functionality. However, a significant concern emerges from the output escaping analysis, where 100% of outputs are not properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if the plugin processes user-supplied data and outputs it without sanitization.

The vulnerability history of "sentence-to-seo" is currently clean, with no recorded CVEs. This absence of past issues is a positive indicator, suggesting a history of responsible development and maintenance. Coupled with the static analysis showing no critical or high severity taint flows, the plugin appears to be free from known critical code execution or data leakage risks at this version. However, the lack of unescaped output remains a notable weakness that could be exploited, especially if combined with other factors or future updates.

In conclusion, "sentence-to-seo" v1.0 demonstrates a promising foundation with its secure SQL handling and clean vulnerability history. The absence of major code flaws in static analysis is encouraging. The paramount weakness lies in the complete lack of output escaping, which introduces a tangible risk of XSS attacks. Developers should prioritize addressing this issue to solidify the plugin's security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
1 published

Sentence To SEO (keywords, description and tags) Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-4142medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Sentence To SEO (keywords, description and tags) <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field

Apr 21, 2026Unpatched
Version History

Sentence To SEO (keywords, description and tags) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Sentence To SEO (keywords, description and tags) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Sentence To SEO (keywords, description and tags) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuindex.php:27
actionadmin_initindex.php:28
Maintenance & Trust

Sentence To SEO (keywords, description and tags) Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 10, 2015
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sentence To SEO (keywords, description and tags) Developer Profile

EazyServer

4 plugins · 40 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sentence To SEO (keywords, description and tags)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<textarea name="sentence"<textarea name="permanent_keywords"<textarea name="stopwords"<td><?php _e("Sentence: "); ?></td>
FAQ

Frequently Asked Questions about Sentence To SEO (keywords, description and tags)