
SEO Search Permalink Security & Risk Analysis
wordpress.org/plugins/seo-search-permalinkChange default search URLs to SEO-friendly URLs, which may enhance your SERP rankings and increase your site traffic. The default URL ?s=keyword will …
Is SEO Search Permalink Safe to Use in 2026?
Use With Caution
Score 63/100SEO Search Permalink has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "seo-search-permalink" v1.0.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by using prepared statements for all SQL queries and performing some nonce and capability checks. However, the output escaping is a significant concern, with only 40% of outputs being properly escaped, indicating a potential for Cross-Site Scripting vulnerabilities if user-supplied data is not handled carefully.
The plugin has a history of known vulnerabilities, with one medium severity Cross-Site Scripting (XSS) vulnerability from 2025-09-26 that remains unpatched. This suggests a pattern of security weaknesses that could be exploited. The absence of critical or high severity vulnerabilities in the past, coupled with the current lack of critical taint flows and dangerous functions, is positive. However, the unpatched medium vulnerability is a direct and present risk.
In conclusion, while the plugin has a limited attack surface and follows some good security practices, the inadequate output escaping and the presence of an unpatched medium severity XSS vulnerability are notable weaknesses. The history of XSS vulnerabilities, even if medium severity, warrants caution. Users should be aware of the potential for XSS and the need for ongoing vigilance regarding patches and updates.
Key Concerns
- Unpatched CVE (Medium)
- Output escaping only 40% proper
SEO Search Permalink Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SEO Search Permalink <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
SEO Search Permalink Code Analysis
Output Escaping
Data Flow Analysis
SEO Search Permalink Attack Surface
WordPress Hooks 7
Maintenance & Trust
SEO Search Permalink Maintenance & Trust
Maintenance Signals
Community Trust
SEO Search Permalink Alternatives
Permalink Manager for WooCommerce
permalink-manager-for-woocommerce
Permalink Manager for WooCommerce improves your store permalinks and remove product, product_category and product_tag slugs from the URL.
Wenprise Pinyin Slug
wenprise-pinyin-slug
自动转换 WordPress 中的中文文章别名、分类项目别名、图片文件名称为汉语拼音或英文翻译。
Change Permalink Helper
change-permalink-helper
It checks the Permalink and redirects to the new URL, if it doesn't exist. It sends the header message "moved permanently 301"
Greek Multi Tool – Greeklish Slugs, Permalinks & Transliteration
greek-multi-tool
The only lightweight plugin you need for Greek WordPress sites. Auto-convert Greeklish slugs, optimize permalinks, and enhance search without bloat.
Advanced Permalinks
advanced-permalinks
Allows multiple permalink structures and category-specific permalinks without needing redirects.
SEO Search Permalink Developer Profile
3 plugins · 630 total installs
How We Detect SEO Search Permalink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seo-search-permalink/inc/css/style.css/wp-content/plugins/seo-search-permalink/inc/js/search-permalink.jsseo-search-permalink/inc/css/style.css?ver=seo-search-permalink/inc/js/search-permalink.js?ver=HTML / DOM Fingerprints
ssp-flexssp-tablessp-table2ssp-labelssp-code-inlinessp-radio-labelSEO SearchPermalink (SSP)Message blockUpdate setting page.Display setting page.+5 moredata-tab="tab1"data-tab="tab2"data-tab="tab3"data-tab="tab4"data-tab="tab5"