
SEOPress for MainWP Security & Risk Analysis
wordpress.org/plugins/seopress-for-mainwpSEOPress for MainWP extension, is an-addon for MainWP and SEOPress plugins. Edit your SEOPress global settings directly from MainWP dashboard site.
Is SEOPress for MainWP Safe to Use in 2026?
Generally Safe
Score 98/100SEOPress for MainWP has a strong security track record. Known vulnerabilities have been patched promptly.
The "seopress-for-mainwp" v1.5 plugin exhibits a generally strong security posture based on the static analysis, with all identified entry points (AJAX handlers) protected by nonce and capability checks. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating a commitment to preventing common web vulnerabilities like SQL injection and cross-site scripting. Furthermore, the absence of file operations and a clean taint analysis with no unsanitized paths are positive indicators.
However, a significant concern arises from the plugin's vulnerability history. A single high-severity Common Vulnerabilities and Exposures (CVE) entry, specifically an Improper Control of Filename for Include/Require Statement (PHP Remote File Inclusion), is a serious red flag. While this vulnerability is noted as currently unpatched, the analysis date (implied by the 2025 CVE date) suggests it might be a future or hypothetical vulnerability. If this historical vulnerability were present and unpatched, it would pose a critical risk. The presence of external HTTP requests, while not inherently insecure, warrants scrutiny in conjunction with other security findings.
In conclusion, the static code analysis reveals robust security practices. Nevertheless, the historical high-severity vulnerability cannot be ignored. While the plugin appears to be well-coded currently, the past existence of a serious vulnerability demands caution and thorough investigation to ensure no residual risks or similar vulnerabilities are present or emerge in future versions. The lack of any current unpatched vulnerabilities is a positive sign, but diligence is still required.
Key Concerns
- Historical high-severity CVE found
SEOPress for MainWP Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SEOPress for MainWP <= 1.4 - Unauthenticated Local File Inclusion
SEOPress for MainWP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SEOPress for MainWP Attack Surface
AJAX Handlers 14
WordPress Hooks 12
Maintenance & Trust
SEOPress for MainWP Maintenance & Trust
Maintenance Signals
Community Trust
SEOPress for MainWP Alternatives
Remote Website Management Plugin by Watchful
watchful
A web developers toolbox for remotely managing and monitoring tens, hundreds, or thousands of WordPress websites at once.
RemoteMonkey
remotemonkey
This is the connector plugin of BackupMonkey.io. It's an external service. TOS: https://backupmonkey.io/en/terms-of-service
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
SEOPress for MainWP Developer Profile
2 plugins · 301K total installs
How We Detect SEOPress for MainWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seopress-for-mainwp/assets/css/seopress-mainwp.css/wp-content/plugins/seopress-for-mainwp/assets/js/seopress-mainwp.js/wp-content/plugins/seopress-for-mainwp/assets/js/seopress-mainwp.jsseopress-for-mainwp/assets/css/seopress-mainwp.css?ver=seopress-for-mainwp/assets/js/seopress-mainwp.js?ver=HTML / DOM Fingerprints
seopress-mainwp-fielddata-seopress-mainwp-id