SEO For Images Security & Risk Analysis

wordpress.org/plugins/seo-for-images

Imporve your images ranking by insert/amend alt and title text, generate solid traffic from search enigine.

70 active installs v1.0.0 PHP + WP 3.2+ Updated Apr 17, 2013
admingoogle-seoimagespostseo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 25, 2025
Safety Verdict

Is SEO For Images Safe to Use in 2026?

Use With Caution

Score 63/100

SEO For Images has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 25, 2025Updated 12yr ago
Risk Assessment

The 'seo-for-images' plugin version 1.0.0 presents a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries use prepared statements, and there are no identified file operations or external HTTP requests. Furthermore, the attack surface appears very small with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication or permission checks.

However, significant concerns arise from the output escaping and vulnerability history. The fact that 100% of the single identified output is not properly escaped is a considerable risk, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. Compounding this, the plugin has a history of one known medium-severity vulnerability, specifically Cross-Site Request Forgery (CSRF), which is currently unpatched. This indicates a pattern of security oversights and a lack of timely remediation for discovered issues.

In conclusion, while the plugin has strengths in its minimal attack surface and secure handling of database operations, the unescaped output and the presence of an unpatched medium-severity CSRF vulnerability are critical weaknesses. Users should exercise caution, and the developers should prioritize addressing the output escaping and the existing CVE.

Key Concerns

  • Unpatched medium severity CVE
  • Output not properly escaped
Vulnerabilities
1

SEO For Images Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48307medium · 4.3Cross-Site Request Forgery (CSRF)

SEO For Images <= 1.0.0 - Cross-Site Request Forgery

Aug 25, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SEO For Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
seo_for_images_options_page (seo-for-images.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SEO For Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuseo-for-images.php:213
filterthe_contentseo-for-images.php:328
actionplugins_loadedseo-for-images.php:349
Maintenance & Trust

SEO For Images Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedApr 17, 2013
PHP min version
Downloads5K

Community Trust

Rating74/100
Number of ratings3
Active installs70
Developer Profile

SEO For Images Developer Profile

kasonzhao

2 plugins · 120 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SEO For Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-for-images/i/wp-content/plugins/seo-for-images/imgs/settings.png

HTML / DOM Fingerprints

CSS Classes
sfi_sidebar
Data Attributes
name="sfiform"id="alt_text"name="alttext"id="title_text"name="titletext"id="check1"+10 more
JS Globals
sfi_plugin_url
FAQ

Frequently Asked Questions about SEO For Images