SEO SIMPLE PACK Security & Risk Analysis

wordpress.org/plugins/seo-simple-pack

This is a very simple SEO plugin. You can easily set and customize meta tags and OGP tags for each page.

100K active installs v3.6.3 PHP 7.0+ WP 4.9+ Updated Apr 1, 2026
analyticsmetameta-tagseowsebmaster
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 27, 2024
Safety Verdict

Is SEO SIMPLE PACK Safe to Use in 2026?

Generally Safe

Score 99/100

SEO SIMPLE PACK has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jun 27, 2024Updated 1mo ago
Risk Assessment

The "seo-simple-pack" plugin v3.6.2 exhibits a generally good security posture based on the provided static analysis, with no identified critical or high-severity code signals like dangerous functions, raw SQL queries, or untainted flows. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events further limits its attack surface. However, a significant weakness lies in its output escaping, with only 76% of outputs properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the unescaped outputs contain user-controlled data. The presence of a single historical CVE, albeit patched and of medium severity, concerning "Exposure of Sensitive Information to an Unauthorized Actor," indicates that the plugin has had past security issues. While the current version appears to have addressed this, it warrants a degree of caution and continued vigilance regarding sensitive data handling.

Key Concerns

  • Output escaping is not 100%
  • 1 medium vulnerability in history
Vulnerabilities
1 published

SEO SIMPLE PACK Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-2795medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

SEO SIMPLE PACK <= 3.2.1 - Information Exposure

Jun 27, 2024 Patched in 3.3.0 (7d)
Version History

SEO SIMPLE PACK Release Timeline

v3.6.3Current29 files changed
v3.6.24 files changed
v3.6.12 files changed
v3.6.020 files changed
v3.5.23 files changed
v3.5.13 files changed
v3.5.011 files changed
v3.4.02 files changed
v3.3.12 files changed
v3.3.03 files changed
v3.2.11 CVE3 files changed
v3.2.01 CVE3 files changed
v3.1.21 CVE2 files changed
v3.1.11 CVE6 files changed
v3.1.01 CVE9 files changed
v3.0.01 CVE11 files changed
v2.5.11 CVE3 files changed
v2.5.01 CVE3 files changed
v2.4.21 CVE3 files changed
v2.4.11 CVE
Code Analysis
Analyzed Mar 16, 2026

SEO SIMPLE PACK Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
112 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped147 total outputs
Attack Surface

SEO SIMPLE PACK Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actioninitclass\hooks.php:14
actionadmin_enqueue_scriptsclass\hooks.php:15
actionadmin_headclass\hooks.php:16
actiontemplate_redirectclass\hooks.php:17
actionadmin_noticesclass\hooks.php:186
actionadmin_menuclass\menu.php:48
actionadd_meta_boxesclass\metabox.php:62
actionsave_postclass\metabox.php:63
actionwp_loadedclass\metabox.php:66
actionedited_termsclass\metabox.php:74
actionwp_headclass\output.php:63
filterpre_get_document_titleclass\output.php:66
actionwp_headclass\output.php:71
actionwpclass\__branch.php:20
actioninitseo-simple-pack.php:59
actionplugins_loadedseo-simple-pack.php:92
Maintenance & Trust

SEO SIMPLE PACK Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.0
Downloads1.2M

Community Trust

Rating92/100
Number of ratings14
Active installs100K
Developer Profile

SEO SIMPLE PACK Developer Profile

Ryo

6 plugins · 135K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect SEO SIMPLE PACK

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seo-simple-pack/dist/css/ssp.css/wp-content/plugins/seo-simple-pack/dist/js/ssp.js/wp-content/plugins/seo-simple-pack/dist/css/post.css/wp-content/plugins/seo-simple-pack/dist/css/term.css/wp-content/plugins/seo-simple-pack/dist/css/common.css/wp-content/plugins/seo-simple-pack/dist/js/switch.js/wp-content/plugins/seo-simple-pack/dist/js/mediauploader.js
Version Parameters
seo-simple-pack/dist/css/ssp.css?ver=seo-simple-pack/dist/js/ssp.js?ver=seo-simple-pack/dist/css/post.css?ver=seo-simple-pack/dist/css/term.css?ver=seo-simple-pack/dist/css/common.css?ver=seo-simple-pack/dist/js/switch.js?ver=seo-simple-pack/dist/js/mediauploader.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssp-notice
FAQ

Frequently Asked Questions about SEO SIMPLE PACK