Sewn In Simple SEO Security & Risk Analysis

wordpress.org/plugins/sewn-in-simple-seo

A very simple SEO interface without caricatures and cruft. New improved social support.

70 active installs v2.1.3 PHP + WP 3.6.1+ Updated Sep 2, 2017
meta-datasearch-engineseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sewn In Simple SEO Safe to Use in 2026?

Generally Safe

Score 85/100

Sewn In Simple SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'sewn-in-simple-seo' version 2.1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the potential attack surface. Furthermore, the code's adherence to using prepared statements for all SQL queries and the presence of a nonce check are positive indicators of secure development practices. The lack of any recorded vulnerabilities or CVEs in its history also suggests a history of secure development and maintenance.

However, a notable concern arises from the output escaping analysis, where only 53% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the taint analysis shows no flows with unsanitized paths, the low percentage of properly escaped output suggests this might be an oversight in the analysis or a latent risk. The bundling of Select2, while a common library, could also pose a minor risk if it's an outdated version and not regularly updated by the plugin author, though this is not explicitly stated in the provided data.

In conclusion, the plugin demonstrates good security fundamentals by minimizing its attack surface and employing prepared statements. The primary area for improvement and potential risk lies in the inconsistent output escaping. Addressing this could further strengthen its security profile. The absence of historical vulnerabilities is a positive sign, but the output escaping issue warrants attention.

Key Concerns

  • Output escaping is not consistently applied
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Sewn In Simple SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sewn In Simple SEO Release Timeline

v2.1.3Current
v2.1.2
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
Code Analysis
Analyzed Mar 16, 2026

Sewn In Simple SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
19 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

53% escaped36 total outputs
Attack Surface

Sewn In Simple SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
filterpre_get_document_titleincludes\class-frontend-seo.php:51
filterwp_titleincludes\class-frontend-seo.php:52
filterloginoutincludes\class-frontend-seo.php:53
filterregisterincludes\class-frontend-seo.php:54
actionadd_meta_boxesincludes\sewn-meta\includes\sewn-meta-boxes.php:84
actionsave_postincludes\sewn-meta\includes\sewn-meta-boxes.php:87
actioninitincludes\sewn-meta\sewn-meta.php:79
actionadmin_enqueue_scriptsincludes\sewn-meta\sewn-meta.php:96
actionadmin_enqueue_scriptsincludes\sewn-meta\sewn-meta.php:97
actionplugins_loadedsewn-simple-seo.php:183
actioninitsewn-simple-seo.php:184
actionwp_loadedsewn-simple-seo.php:185
filtersewn/seo/archive_titlesewn-simple-seo.php:186
actionadmin_enqueue_scriptssewn-simple-seo.php:238
actionwp_headsewn-simple-seo.php:241
Maintenance & Trust

Sewn In Simple SEO Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 2, 2017
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs70
Developer Profile

Sewn In Simple SEO Developer Profile

Jupitercow

8 plugins · 510 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sewn In Simple SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sewn-in-simple-seo/assets/css/sewn-meta.css/wp-content/plugins/sewn-in-simple-seo/assets/js/sewn-meta.js
Script Paths
/wp-content/plugins/sewn-in-simple-seo/assets/js/sewn-meta.js/wp-content/plugins/sewn-in-simple-seo/assets/js/select2.min.js
Version Parameters
sewn-in-simple-seo/assets/css/select2.min.css?ver=sewn-in-simple-seo/assets/css/sewn-meta.css?ver=sewn-in-simple-seo/assets/js/select2.min.js?ver=sewn-in-simple-seo/assets/js/sewn-meta.js?ver=

HTML / DOM Fingerprints

CSS Classes
sewn-seo-meta-titlesewn-seo-meta-descriptionsewn-seo-meta-keywords
Data Attributes
data-sewn-seo-meta-titledata-sewn-seo-meta-descriptiondata-sewn-seo-meta-keywords
FAQ

Frequently Asked Questions about Sewn In Simple SEO