
SEO Friendly Images Security & Risk Analysis
wordpress.org/plugins/seo-imageSEO Friendly Images automatically adds alt and title attributes to all your images improving traffic from search engines.
Is SEO Friendly Images Safe to Use in 2026?
Use With Caution
Score 61/100SEO Friendly Images has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "seo-image" v3.0.5 plugin exhibits a generally strong security posture based on the static analysis. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the attack surface. Furthermore, the code appears to utilize prepared statements for all SQL queries and performs a single nonce check, indicating some awareness of security best practices. The lack of dangerous functions, file operations, and external HTTP requests also contributes to a positive security outlook.
However, a significant concern arises from the extremely low percentage (1%) of properly escaped output. With 144 total outputs, this implies a vast majority of user-supplied or dynamically generated content is being rendered without proper sanitization, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Although no critical or high severity taint flows were detected in the analyzed flows, the output escaping issue presents a direct and prevalent threat.
The plugin's vulnerability history, while showing only one past medium-severity XSS vulnerability from a considerable time ago (2015), doesn't entirely alleviate concerns given the current static analysis findings. The historical XSS vulnerability reinforces the potential for such issues, and the current lack of proper output escaping strongly suggests that new XSS vulnerabilities could easily be introduced or may already exist. The good news is that there are no currently unpatched vulnerabilities. In conclusion, while the plugin benefits from a limited attack surface and good SQL practices, the pervasive lack of output escaping is a critical weakness that requires immediate attention.
Key Concerns
- Extremely low output escaping percentage (1%)
- Past medium severity XSS vulnerability
SEO Friendly Images Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SEO Friendly Images <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
SEO Friendly Images <= 3.0.4 - Cross-Site Request Forgery to Cross-Site Scripting
SEO Friendly Images Release Timeline
SEO Friendly Images Code Analysis
Output Escaping
Data Flow Analysis
SEO Friendly Images Attack Surface
WordPress Hooks 5
Maintenance & Trust
SEO Friendly Images Maintenance & Trust
Maintenance Signals
Community Trust
SEO Friendly Images Alternatives
SEO For Images
seo-for-images
Imporve your images ranking by insert/amend alt and title text, generate solid traffic from search enigine.
DOM SEO Image
dom-seo-image
DOM SEO Image automatically adds alt and title attributes to all your images improving traffic from search engines.
Insights
insights
Insights allows you to quickly access and insert information (links, images, videos, maps..) into your blog posts.
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)
bulk-image-alt-text-with-yoast
Automatic alt text for WordPress and WooCommerce. Dynamic, reversible, and based on your existing SEO context from Yoast, Rank Math, or AIOSEO.
Require Featured Image
require-featured-image
Requires content you specify to have a featured image set before they can be published.
SEO Friendly Images Developer Profile
19 plugins · 30K total installs
How We Detect SEO Friendly Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seo-image/i/arrows.png/wp-content/plugins/seo-image/i/logo.png/wp-content/plugins/seo-image/i/icon.png/wp-content/plugins/seo-image/javascripts/sfi.jsseo-image/style.css?ver=seo-image/script.js?ver=HTML / DOM Fingerprints
settingsholdercollineline2regular-textsmallsmaller+1 moreid="title_global"id="defualt_settings"id="mainblock"id="default_override_div"id="global_settings"id="default_attach_internal_images_div"+6 moreSEOFriendlyImages