Soro – SEO Autopilot & AI Content Writer Security & Risk Analysis

wordpress.org/plugins/soro-seo

Connect your WordPress site to Soro for automatic AI-powered article publishing and SEO content automation.

500 active installs v1.3.5 PHP 7.4+ WP 5.0+ Updated Feb 22, 2026
aiautomationcontentpublishingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Soro – SEO Autopilot & AI Content Writer Safe to Use in 2026?

Generally Safe

Score 100/100

Soro – SEO Autopilot & AI Content Writer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "soro-seo" plugin v1.3.5 demonstrates a generally strong security posture based on the provided static analysis. The absence of unprotected entry points, dangerous functions, raw SQL queries, and critical taint flows is highly encouraging. The plugin also shows good practices with nearly all output being properly escaped and the use of nonce and capability checks on its limited entry points.

However, there are a few minor areas of potential concern. The presence of file operations, even without explicit vulnerability history, could be a vector for abuse if not handled with extreme care. While the vulnerability history is clean, indicating a good track record, this doesn't negate the need for continuous vigilance. The limited attack surface is a positive, but the existence of 4 REST API routes without explicit permission callbacks (even though the analysis states 0 without them) warrants a closer look to ensure these are indeed protected.

Overall, "soro-seo" v1.3.5 appears to be a well-secured plugin. The developer seems to have implemented good security practices, resulting in a clean vulnerability history and robust code signals. The primary areas to monitor would be the secure handling of file operations and verifying the absolute protection of all REST API routes.

Key Concerns

  • File operations present
  • REST API routes without permission callbacks (potentially)
Vulnerabilities
None known

Soro – SEO Autopilot & AI Content Writer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Soro – SEO Autopilot & AI Content Writer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
32 escaped
Nonce Checks
3
Capability Checks
4
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped34 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
handle_save_author (soro-seo.php:334)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Soro – SEO Autopilot & AI Content Writer Attack Surface

Entry Points4
Unprotected0

REST API Routes 4

POST/wp-json/soro/v1/publishsoro-seo.php:563
GET/wp-json/soro/v1/verifysoro-seo.php:569
POST/wp-json/soro/v1/setup-indexnowsoro-seo.php:575
GET/wp-json/soro/v1/indexnow-statussoro-seo.php:581
WordPress Hooks 7
actionadmin_menusoro-seo.php:31
actionadmin_initsoro-seo.php:32
actionadmin_initsoro-seo.php:33
actionadmin_initsoro-seo.php:34
actionadmin_initsoro-seo.php:35
actionadmin_enqueue_scriptssoro-seo.php:36
actionrest_api_initsoro-seo.php:37
Maintenance & Trust

Soro – SEO Autopilot & AI Content Writer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Soro – SEO Autopilot & AI Content Writer Developer Profile

soroseo

1 plugin · 500 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Soro – SEO Autopilot & AI Content Writer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/soro-seo/assets/css/soro-admin.css/wp-content/plugins/soro-seo/assets/js/soro-admin.js
Script Paths
/wp-content/plugins/soro-seo/assets/js/soro-admin.js
Version Parameters
soro-seo/assets/css/soro-admin.css?ver=soro-seo/assets/js/soro-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
soro-wrapsoro-logosoro-cardsoro-card-headersoro-statussoro-status-dotsoro-key-containersoro-key+5 more
Data Attributes
data-copied-textdata-copy-text
JS Globals
soroCopyKey
REST Endpoints
/wp-json/soro-connector/v1/settings
FAQ

Frequently Asked Questions about Soro – SEO Autopilot & AI Content Writer