SEO Search Permalink Security & Risk Analysis

wordpress.org/plugins/seo-search-permalink

Change default search URLs to SEO-friendly URLs, which may enhance your SERP rankings and increase your site traffic. The default URL ?s=keyword will …

30 active installs v1.0.3 PHP 5.3.0+ WP 4.0+ Updated May 11, 2023
permalinksearch-permalinksearch-urlseo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is SEO Search Permalink Safe to Use in 2026?

Use With Caution

Score 63/100

SEO Search Permalink has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 2yr ago
Risk Assessment

The "seo-search-permalink" v1.0.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by using prepared statements for all SQL queries and performing some nonce and capability checks. However, the output escaping is a significant concern, with only 40% of outputs being properly escaped, indicating a potential for Cross-Site Scripting vulnerabilities if user-supplied data is not handled carefully.

The plugin has a history of known vulnerabilities, with one medium severity Cross-Site Scripting (XSS) vulnerability from 2025-09-26 that remains unpatched. This suggests a pattern of security weaknesses that could be exploited. The absence of critical or high severity vulnerabilities in the past, coupled with the current lack of critical taint flows and dangerous functions, is positive. However, the unpatched medium vulnerability is a direct and present risk.

In conclusion, while the plugin has a limited attack surface and follows some good security practices, the inadequate output escaping and the presence of an unpatched medium severity XSS vulnerability are notable weaknesses. The history of XSS vulnerabilities, even if medium severity, warrants caution. Users should be aware of the potential for XSS and the need for ongoing vigilance regarding patches and updates.

Key Concerns

  • Unpatched CVE (Medium)
  • Output escaping only 40% proper
Vulnerabilities
1

SEO Search Permalink Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60184medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SEO Search Permalink <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SEO Search Permalink Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ssp_update_form_options (inc\setting.php:29)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SEO Search Permalink Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesinc\setting.php:38
actionadmin_noticesinc\setting.php:89
filtersearch_rewrite_rulesseo-search-permalink.php:90
actionadmin_menuseo-search-permalink.php:91
actiontemplate_redirectseo-search-permalink.php:92
actionpre_get_postsseo-search-permalink.php:93
actioninitseo-search-permalink.php:96
Maintenance & Trust

SEO Search Permalink Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.0
Last updatedMay 11, 2023
PHP min version5.3.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

SEO Search Permalink Developer Profile

Terry L.

3 plugins · 630 total installs

64
trust score
Avg Security Score
78/100
Avg Patch Time
1100 days
View full developer profile
Detection Fingerprints

How We Detect SEO Search Permalink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-search-permalink/inc/css/style.css
Script Paths
/wp-content/plugins/seo-search-permalink/inc/js/search-permalink.js
Version Parameters
seo-search-permalink/inc/css/style.css?ver=seo-search-permalink/inc/js/search-permalink.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssp-flexssp-tablessp-table2ssp-labelssp-code-inlinessp-radio-label
HTML Comments
SEO SearchPermalink (SSP)Message blockUpdate setting page.Display setting page.+5 more
Data Attributes
data-tab="tab1"data-tab="tab2"data-tab="tab3"data-tab="tab4"data-tab="tab5"
FAQ

Frequently Asked Questions about SEO Search Permalink