SEO Bulk Admin Security & Risk Analysis

wordpress.org/plugins/seo-bulk-admin

Easily manage posts, pages, and WooCommerce products with SEO Bulk Admin. Bulk assign categories and tags, delete posts, categories, tags, and more.

10 active installs v1.3.0 PHP 7.0+ WP 6.2+ Updated Jan 21, 2026
bulk-editredirectredirectionsearch-replaceseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SEO Bulk Admin Safe to Use in 2026?

Generally Safe

Score 100/100

SEO Bulk Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "seo-bulk-admin" v1.3.0 plugin exhibits a generally good security posture with a strong emphasis on prepared statements for SQL queries and a significant number of output escaping operations. The presence of nonce and capability checks, along with a limited number of entry points, further bolsters its defenses. Crucially, there is no recorded vulnerability history, suggesting a lack of significant security flaws discovered to date, which is a positive indicator.

However, a concerning aspect is the relatively low percentage of properly escaped outputs (59%). This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the unescaped outputs. While the taint analysis shows no unsanitized flows, the static analysis highlights an area for improvement in output sanitization.

Overall, the plugin demonstrates sound security practices, particularly in its database interactions and authentication checks. The primary area of concern lies in the incomplete output escaping, which warrants attention to prevent potential XSS attacks. The absence of historical vulnerabilities is encouraging, but the identified code signals should still be addressed to ensure a robust security profile.

Key Concerns

  • Low percentage of properly escaped outputs
Vulnerabilities
None known

SEO Bulk Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SEO Bulk Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
14
46 prepared
Unescaped Output
257
373 escaped
Nonce Checks
1
Capability Checks
3
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

77% prepared60 total queries

Output Escaping

59% escaped630 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
home_tab (class-tacwp-postmgr-core.php:3280)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SEO Bulk Admin Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_tacwp_postmgr_ajax_handlerclass-tacwp-postmgr-core.php:1773
WordPress Hooks 22
actionadmin_enqueue_scriptsclass-tacwp-postmgr-core.php:1231
actionadmin_initclass-tacwp-postmgr-core.php:4052
actionadmin_menuclass-tacwp-postmgr-core.php:4053
actioninitclass-tacwp-postmgr-core.php:4054
actionafter_setup_themeclass-tacwp-postmgr-core.php:4055
filterplugin_action_linksclass-tacwp-postmgr-core.php:4056
actionwp_headclass-tacwp-postmgr-core.php:4059
filtermanage_post_posts_columnsclass-tacwp-postmgr-core.php:4061
filtermanage_post_posts_custom_columnclass-tacwp-postmgr-core.php:4062
actioninitclass-tacwp-postmgr-core.php:4063
actioninitclass-tacwp-postmgr-core.php:4065
actionadmin_initclass-tacwp-postmgr-core.php:4118
actionadmin_noticesclass-tacwp-postmgr-core.php:4119
filtercron_schedulesclass-tacwp-postmgr-core.php:4122
actionseoba_process_eventsclass-tacwp-postmgr-core.php:4123
actionpre_get_postsclass-tacwp-postmgr-core.php:4127
actionpre_get_postsclass-tacwp-postmgr-core.php:4128
filterposts_searchclass-tacwp-postmgr-core.php:4942
filterposts_joinclass-tacwp-postmgr-core.php:4943
filterposts_distinctclass-tacwp-postmgr-core.php:4944
actionadmin_noticesclass-tacwp-postmgr-core.php:5300
actionadmin_noticesclass-tacwp-postmgr-core.php:5343

Scheduled Events 1

seoba_process_events
Maintenance & Trust

SEO Bulk Admin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

SEO Bulk Admin Developer Profile

ampwptools

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SEO Bulk Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-bulk-admin/css/postmgr.css/wp-content/plugins/seo-bulk-admin/js/postmgr.js/wp-content/plugins/seo-bulk-admin/js/bootstrap.bundle.min.js/wp-content/plugins/seo-bulk-admin/js/jquery.min.js/wp-content/plugins/seo-bulk-admin/js/select2.full.min.js
Generator Patterns
SEO Bulk Admin
Script Paths
/wp-content/plugins/seo-bulk-admin/js/postmgr.js/wp-content/plugins/seo-bulk-admin/js/bootstrap.bundle.min.js/wp-content/plugins/seo-bulk-admin/js/jquery.min.js/wp-content/plugins/seo-bulk-admin/js/select2.full.min.js
Version Parameters
seo-bulk-admin/css/postmgr.css?ver=seo-bulk-admin/js/postmgr.js?ver=seo-bulk-admin/js/bootstrap.bundle.min.js?ver=seo-bulk-admin/js/jquery.min.js?ver=seo-bulk-admin/js/select2.full.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
tacwp-postmgr-main
HTML Comments
SEO Bulk Admin compiled project class file.Base class for project (theme or plugin).
Data Attributes
data-post-typedata-user-iddata-term-typedata-action-urldata-nonce
JS Globals
tacwp_postmgr_opts
FAQ

Frequently Asked Questions about SEO Bulk Admin