
Site Suggest Security & Risk Analysis
wordpress.org/plugins/site-suggestSite Suggest is a comprehensive WordPress plugin designed to assist site administrators in reviewing and optimizing their site's SEO analytics.
Is Site Suggest Safe to Use in 2026?
Mostly Safe
Score 78/100Site Suggest is generally safe to use. 1 past CVE were resolved.
The "site-suggest" v1.3.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped, and a high percentage of SQL queries utilizing prepared statements. The absence of dangerous functions and bundled libraries also contributes to a generally cleaner codebase. However, significant concerns arise from the attack surface analysis. With 24 AJAX handlers, 7 of which lack authentication checks, there is a substantial risk of unauthorized actions being performed. This is further underscored by the taint analysis, which identified one flow with unsanitized paths. The vulnerability history, while showing only one medium-severity CVE, indicates a past issue related to missing authorization. The presence of an unpatched CVE is a critical red flag, suggesting ongoing exposure to a known security flaw. The pattern of past vulnerabilities and the current lack of authentication on several AJAX endpoints point to a potential recurring issue with authorization enforcement.
Key Concerns
- Unprotected AJAX handlers (7)
- Flow with unsanitized paths
- Unpatched CVE (medium severity)
- Missing capability checks on AJAX handlers
Site Suggest Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Site Suggest <= 1.3.9 - Missing Authorization
Site Suggest Release Timeline
Site Suggest Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Site Suggest Attack Surface
AJAX Handlers 24
WordPress Hooks 21
Scheduled Events 1
Maintenance & Trust
Site Suggest Maintenance & Trust
Maintenance Signals
Community Trust
Site Suggest Alternatives
Facilitated Routines
facilitated-routines
Automate technical SEO, image optimization and webp creation, security, unused media cleanup, sitemaps, find broken links, and more.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Insights from Google PageSpeed
google-pagespeed-insights
Use Insights from Google PageSpeed to increase your sites performance, your search engine ranking, and your visitors browsing experience.
AF Companion – Starter Sites, Speed Booster & Growth Suite for Professional Publishing
af-companion
One-Click Starter Sites, Performance Optimization, and Publisher Growth Tools
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
Site Suggest Developer Profile
2 plugins · 150 total installs
How We Detect Site Suggest
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-suggest/app/public/css/site-suggest.css/wp-content/plugins/site-suggest/app/public/js/site-suggest.js/wp-content/plugins/site-suggest/app/public/js/site-suggest.jssite-suggest/app/public/css/site-suggest.css?ver=site-suggest/app/public/js/site-suggest.js?ver=HTML / DOM Fingerprints
stsgt_dismiss_admin_notice<!-- SiteSuggest -->data-stsgt-dismissdata-stsgt-noncedata-stsgt-actionstsgt_vars