SEO Image Toolbox Security & Risk Analysis

wordpress.org/plugins/seo-image-alt-tags

THIS WILL SAVE YOU HOURS. Alt tags are dynamically generated and saved to the database automatically any time an image is uploaded, and improves your …

1K active installs v3.3.1 PHP + WP 3.0+ Updated Apr 10, 2018
image-seoimage-tagsoptimize-imagesseoseo-images
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SEO Image Toolbox Safe to Use in 2026?

Generally Safe

Score 85/100

SEO Image Toolbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "seo-image-alt-tags" v3.3.1 plugin exhibits a strong static security posture based on the provided analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals reveal no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are positive indicators of secure coding practices.

However, the analysis does highlight a significant concern regarding output escaping. With 16 total outputs and only 25% properly escaped, there's a high probability of cross-site scripting (XSS) vulnerabilities. This lack of proper sanitization on a quarter of the outputs represents a clear and present risk. The vulnerability history being clean is a positive sign, suggesting the developers have historically maintained a secure codebase or that the plugin hasn't been a target for exploits.

In conclusion, while the plugin benefits from a minimal attack surface and the absence of common risky code patterns, the substantial percentage of unescaped output is a critical weakness. This requires immediate attention to mitigate the risk of XSS attacks, which could have serious security implications for users of the plugin. The clean vulnerability history is encouraging, but the identified output escaping issues should not be overlooked.

Key Concerns

  • High percentage of unescaped output
Vulnerabilities
None known

SEO Image Toolbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SEO Image Toolbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped16 total outputs
Attack Surface

SEO Image Toolbox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_footerclasses\class-sit-scripts.php:12
actionadmin_menuclasses\class-sit-settings.php:20
actionadmin_initclasses\class-sit-settings.php:21
filterplugin_action_linksseo-image-alt-tags.php:35
filteradd_attachmentseo-image-alt-tags.php:63
Maintenance & Trust

SEO Image Toolbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 10, 2018
PHP min version
Downloads42K

Community Trust

Rating86/100
Number of ratings12
Active installs1K
Developer Profile

SEO Image Toolbox Developer Profile

Andrew Gunn

9 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SEO Image Toolbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-sit-id
JS Globals
sit_settings
FAQ

Frequently Asked Questions about SEO Image Toolbox