SEO.AI Publisher Security & Risk Analysis

wordpress.org/plugins/seo-ai-publisher

Connect your WordPress site to SEO.AI platform to automatically receive and publish optimized blog content.

200 active installs v1.1.3 PHP 7.0+ WP 6.4+ Updated Mar 11, 2026
apiautomationcontentpublishingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SEO.AI Publisher Safe to Use in 2026?

Generally Safe

Score 100/100

SEO.AI Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "seo-ai-publisher" v1.1.3 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of unprotected entry points (AJAX handlers, REST API routes, shortcodes) and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks indicate good development practices aimed at preventing common web vulnerabilities. The lack of any recorded vulnerabilities, including CVEs, further reinforces this positive assessment.

While the analysis shows no critical or high-severity issues, there are a few points to consider. The presence of external HTTP requests, although not explicitly flagged as a vulnerability, could be a potential attack vector if the target servers are compromised or if the plugin blindly trusts the content of these requests. The two cron events, while not directly identified as unprotected, warrant a closer look to ensure they do not introduce unforeseen risks during their execution. The limited scope of the taint analysis (only 1 flow analyzed) means that deeper, more complex taint flows might remain undiscovered.

In conclusion, "seo-ai-publisher" v1.1.3 appears to be a well-secured plugin with a strong emphasis on preventing common WordPress vulnerabilities. Its robust handling of SQL, output escaping, and protected entry points are commendable. However, the presence of external HTTP requests and the limited scope of the taint analysis suggest that a continued vigilant approach to security, including regular updates and monitoring, is always advisable for any plugin.

Key Concerns

  • External HTTP requests present, potential vector
  • Limited taint flow analysis, potential hidden risks
Vulnerabilities
None known

SEO.AI Publisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SEO.AI Publisher Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

SEO.AI Publisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
50 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped51 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<Admin> (src\Admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SEO.AI Publisher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionplugins_loadedseo-ai-publisher.php:36
filterseoai_publisher_is_restsrc\Api.php:320
filterallowed_redirect_hostssrc\Auth.php:135
actionadmin_menusrc\Main.php:49
actionadmin_enqueue_scriptssrc\Main.php:50
actionadmin_initsrc\Main.php:51
actionadmin_initsrc\Main.php:52
actionadmin_noticessrc\Main.php:53
actionrest_api_initsrc\Main.php:63
actionrest_api_initsrc\Main.php:68
actioninitsrc\Main.php:100
actionadd_attachmentsrc\MinimalBlockConverter.php:148
filterdownload_url_error_max_body_sizesrc\PostHandler.php:250
actionsave_postsrc\Webhook.php:36
actionwp_trash_postsrc\Webhook.php:39
actionbefore_delete_postsrc\Webhook.php:42
actionseoai_publisher_process_webhook_queuesrc\Webhook.php:45
actionshutdownsrc\Webhook.php:48
actionupgrader_process_completesrc\Webhook.php:51
actionadmin_noticessrc\Webhook.php:55

Scheduled Events 2

seoai_publisher_process_webhook_queue
seoai_publisher_process_webhook_queue
Maintenance & Trust

SEO.AI Publisher Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

SEO.AI Publisher Developer Profile

seoai

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SEO.AI Publisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-ai-publisher/admin/assets/css/admin.css/wp-content/plugins/seo-ai-publisher/admin/assets/js/admin.js
Script Paths
/wp-content/plugins/seo-ai-publisher/admin/assets/js/admin.js
Version Parameters
seo-ai-publisher?ver=admin/assets/css/admin.css?ver=admin/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="seoai_publisher_api_key"id="seoai_publisher_api_key"data-action="save_api_key"
JS Globals
seoai_publisher_admin
FAQ

Frequently Asked Questions about SEO.AI Publisher