
Site-First SEO Security & Risk Analysis
wordpress.org/plugins/site-first-seoImprove on-site SEO with your site’s own data: titles/meta, internal links, visits, redirects & 404s.
Is Site-First SEO Safe to Use in 2026?
Generally Safe
Score 100/100Site-First SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'site-first-seo' plugin v1.0.10 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has a small attack surface with only two shortcodes identified as entry points, and importantly, none of these are reported as unprotected. The absence of any known CVEs and a clean vulnerability history further bolster its security reputation, suggesting a well-maintained and secure codebase over time. Furthermore, the code analysis indicates robust security practices, with a high percentage of SQL queries using prepared statements and a significant number of nonce and capability checks, demonstrating a commitment to preventing common WordPress vulnerabilities.
However, there are minor areas for improvement. While the overall output escaping is high, 37% of outputs are not properly escaped, which could present a risk if any of these outputs handle user-supplied data without further sanitization. The presence of file operations and external HTTP requests, although not inherently problematic, warrant careful review to ensure they are implemented securely and do not introduce vulnerabilities. The taint analysis revealing no critical or high severity unsanitized flows is a strong positive sign, indicating that potentially dangerous data flows are being handled appropriately.
In conclusion, 'site-first-seo' v1.0.10 appears to be a secure plugin with a strong foundation in WordPress security best practices. The minimal attack surface, lack of historical vulnerabilities, and strong use of prepared statements and checks are commendable. The primary area of concern is the unescaped output, which should be addressed to achieve a perfect security score.
Key Concerns
- Unescaped output detected
Site-First SEO Security Vulnerabilities
Site-First SEO Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Site-First SEO Attack Surface
Shortcodes 2
WordPress Hooks 112
Maintenance & Trust
Site-First SEO Maintenance & Trust
Maintenance Signals
Community Trust
Site-First SEO Alternatives
Post to Google My Business (Google Business Profile)
post-to-google-my-business
Auto-publish posts, pages & CPTs, plus manage Google Business Profile posts. All from your WordPress dashboard!
Five Star Business Profile and Schema
business-profile
Add structured data to any page or post type. Create an SEO friendly contact card with your business info and associated schema.
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
metasync
Search Atlas SEO is a user-friendly WordPress plugin that simplifies complex and time-consuming SEO tasks into efficient, easy-to-manage processes.
Better Robots.txt – AI-Ready Crawl Control & Bot Governance
better-robots-txt
Replace the default WordPress robots.txt workflow with a smarter, structured version you can preview before publishing, with Free, Pro, and Premium ed …
Bulk Page Generator – LPagery
lpagery
Effortlessly mass generate unlimited SEO-optimized pages in bulk with LPagery. Boost traffic, save time, and grow your business in just 5 minutes!
Site-First SEO Developer Profile
4 plugins · 10 total installs
How We Detect Site-First SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-first-seo/assets/js/sfseo-script.js/wp-content/plugins/site-first-seo/assets/css/sfseo-style.cssSite-First SEO v1.0.10/wp-content/plugins/site-first-seo/assets/js/sfseo-script.jssite-first-seo/assets/css/sfseo-style.css?ver=site-first-seo/assets/js/sfseo-script.js?ver=HTML / DOM Fingerprints
sfseo-settingsSite-First SEOSFSEOdata-sfseo-inputdata-sfseo-labelsfseo_vars/wp-json/sfseo/v1/settings