Simple Meta Tags Security & Risk Analysis

wordpress.org/plugins/simple-meta-tags

Allows you to set global meta tags and customize on each individual page/post. Please Note: Does not support custom post types

800 active installs v1.5 PHP + WP 3.1+ Updated May 14, 2021
descriptionhotscotkeywordsmeta-tagsseo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 26, 2025
Download
Safety Verdict

Is Simple Meta Tags Safe to Use in 2026?

Use With Caution

Score 63/100

Simple Meta Tags has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 4yr ago
Risk Assessment

The static analysis of the 'simple-meta-tags' plugin v1.5 reveals a seemingly strong security posture in several areas. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant positive. Furthermore, the plugin exclusively uses prepared statements for SQL queries and performs no file operations or external HTTP requests, indicating good defensive coding practices against common web vulnerabilities. However, the static analysis also flags a critical concern: only 18% of output is properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially considering the plugin's vulnerability history.

The vulnerability history further amplifies these concerns. The presence of one currently unpatched medium-severity CVE, specifically an Improper Neutralization of Input During Web Page Generation (XSS), directly correlates with the low output escaping percentage found in the static analysis. This suggests that a known security flaw, likely related to unescaped user input being rendered in the browser, has not been addressed. The plugin's single known CVE is also relatively recent, indicating a potential pattern of security oversights that need to be rectified promptly. While the plugin exhibits good practices in some areas, the unpatched XSS vulnerability and the widespread lack of output escaping pose a significant risk to users.

Key Concerns

  • Unpatched Medium Severity CVE
  • Low output escaping (18%)
Vulnerabilities
1

Simple Meta Tags Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60142medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Meta Tags <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Simple Meta Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped17 total outputs
Attack Surface

Simple Meta Tags Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initsimple-meta-tags.php:29
actionadmin_menusimple-meta-tags.php:30
actionadd_meta_boxessimple-meta-tags.php:31
actionsave_postsimple-meta-tags.php:32
actionwp_headsimple-meta-tags.php:35
Maintenance & Trust

Simple Meta Tags Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 14, 2021
PHP min version
Downloads38K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

Simple Meta Tags Developer Profile

DaganLev

3 plugins · 11K total installs

63
trust score
Avg Security Score
77/100
Avg Patch Time
624 days
View full developer profile
Detection Fingerprints

How We Detect Simple Meta Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-meta-tags/css/simple-meta-tags.css/wp-content/plugins/simple-meta-tags/js/simple-meta-tags.js
Script Paths
/wp-content/plugins/simple-meta-tags/js/simple-meta-tags.js
Version Parameters
simple-meta-tags/css/simple-meta-tags.css?ver=simple-meta-tags/js/simple-meta-tags.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="page_meta_title"id="page_meta_title"name="page_meta_description"id="page_meta_description"name="page_meta_keywords"id="page_meta_keywords"+10 more
FAQ

Frequently Asked Questions about Simple Meta Tags