
SEO Plugin by Squirrly SEO Security & Risk Analysis
wordpress.org/plugins/squirrly-seoRank without begging Google. AI-powered SEO that actually helps you win. Trusted by rebels, creators, and pros in 150+ countries.
Is SEO Plugin by Squirrly SEO Safe to Use in 2026?
Generally Safe
Score 88/100SEO Plugin by Squirrly SEO has a strong security track record. Known vulnerabilities have been patched promptly.
The Squirrly SEO plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation and a healthy number of output escaping checks, significant concerns arise from its unprotected entry points and critical taint analysis findings. The presence of unprotected REST API routes is a major vulnerability, as these can be exploited by unauthenticated attackers. The taint analysis revealing multiple flows with unsanitized paths, even if not classified as critical or high severity in the provided data, indicates potential for vulnerabilities if these paths are exploited. The plugin's history of 14 known CVEs, particularly the prevalence of SQL Injection, XSS, and authorization bypasses, highlights a recurring pattern of security weaknesses that demand attention. Although there are no currently unpatched CVEs, the historical trend suggests a need for more robust security development and testing processes. The use of the `unserialize` function also presents a potential risk if user-controlled data is unserialized without proper validation.
In conclusion, while the plugin shows strengths in areas like SQL sanitization, the unprotected attack surface and concerning taint analysis results, coupled with a history of diverse and impactful vulnerabilities, elevate the risk profile. The lack of authorization checks on multiple REST API routes is a critical flaw that needs immediate remediation. The historical vulnerability patterns suggest ongoing challenges in securely handling user input and enforcing proper authorization, which could lead to future exploitable issues. Developers should prioritize securing all entry points and addressing the identified taint flows to improve the overall security of the plugin.
Key Concerns
- Unprotected REST API routes
- Flows with unsanitized paths
- Dangerous function: unserialize
- Low output escaping percentage
- Bundled library: DataTables
- Historical CVEs (High severity)
- Historical CVEs (Medium severity)
SEO Plugin by Squirrly SEO Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
SEO Plugin by Squirrly SEO <= 12.4.14 - Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection
SEO Plugin by Squirrly SEO <= 12.4.03 - Authenticated (Contributor+) SQL Injection
SEO Plugin by Squirrly SEO <= 12.4.05 - Authenticated (Subscriber+) SQL Injection via search Parameter
SEO Plugin by Squirrly SEO <= 12.4.07 - Missing Authorization
SEO Plugin by Squirrly SEO <= 12.3.20 - Authenticated (Editor+) Stored Cross-Site Scripting
SEO Plugin by Squirrly SEO <= 12.3.19 - Authenticated (Contributor+) SQL Injection via url Parameter
SEO Plugin by Squirrly SEO <= 12.3.16 - Reflected Cross-Site Scripting
SEO Plugin by Squirrly SEO <= 12.3.15 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings
SEO Plugin by Squirrly SEO <= 12.1.20 - Reflected Cross-Site Scripting via 'page' and 'tab'
SEO Plugin by Squirrly SEO <= 12.1.20 - Missing Authorization
SEO Plugin by Squirrly SEO <= 12.1.10 - Authenticated (Contributor+) Arbitrary File Upload
SEO Plugin by Squirrly SEO <= 11.1.11 - Reflected Cross-Site Scripting
SEO Plugin by Squirrly SEO < 6.1.5 - Missing Authorization Checks
SEO Plugin by Squirrly SEO < 6.1.5 - Directory Traversal
SEO Plugin by Squirrly SEO Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
SEO Plugin by Squirrly SEO Attack Surface
REST API Routes 3
WordPress Hooks 254
Scheduled Events 1
Maintenance & Trust
SEO Plugin by Squirrly SEO Maintenance & Trust
Maintenance Signals
Community Trust
SEO Plugin by Squirrly SEO Alternatives
SEOPress – On-site SEO & Analytics
wp-seopress
SEOPress, a simple, fast and powerful all in one SEO plugin for WordPress. Rank higher in search engines, fully white label. Now with AI.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
Xagio SEO – AI Powered SEO
xagio-seo
Xagio is the only WordPress SEO plugin built with AI to help you rank fast, rank higher, and optimize for SEO using advanced AI for insane SEO results …
ImgSEO – AI Image Alt Text Generator & Image SEO Tools
imgseo-ai-alt-text-generator
Context-aware AI that analyzes both images and page content for accurate metadata. Process 1000+ images with 16x faster parallel processing.
SEO Plugin by Squirrly SEO Developer Profile
5 plugins · 50K total installs
How We Detect SEO Plugin by Squirrly SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/squirrly-seo/assets/css/seosettings.css/wp-content/plugins/squirrly-seo/assets/css/bulkseo.css/wp-content/plugins/squirrly-seo/assets/css/labels.css/wp-content/plugins/squirrly-seo/assets/css/highlight.css/wp-content/plugins/squirrly-seo/assets/js/seosettings.js/wp-content/plugins/squirrly-seo/assets/js/bulkseo.js/wp-content/plugins/squirrly-seo/assets/js/labels.js/wp-content/plugins/squirrly-seo/assets/js/highlight.js+2 more/wp-content/plugins/squirrly-seo/assets/js/seosettings.js/wp-content/plugins/squirrly-seo/assets/js/bulkseo.js/wp-content/plugins/squirrly-seo/assets/js/labels.js/wp-content/plugins/squirrly-seo/assets/js/highlight.js/wp-content/plugins/squirrly-seo/assets/js/editor.js/wp-content/plugins/squirrly-seo/assets/js/post.jssquirrly-seo/assets/css/squirrly-seo/assets/js/squirrly-seo/classes/DisplayController.php?ver=squirrly-seo/controllers/Assistant.php?ver=HTML / DOM Fingerprints
sq_assistant_tabsq_bulk_seosq_highlight_blocksq_settings_boxsq_help_boxsq_seo_automation_modal<!-- Squirrly SEO v12.4.16 --><!-- Squirrly SEO Content Optimization --><!-- Squirrly SEO Assistant --><!-- Squirrly SEO Bulk Editor -->+1 moredata-sq-editor-initdata-sq-bulk-seo-initdata-sq-assistant-tabdata-sq-highlight-enablesq_settingssq_bulk_seosq_assistantsq_highlight/wp-json/squirrly-seo/v1/settings/wp-json/squirrly-seo/v1/optimizer/wp-json/squirrly-seo/v1/bulk/wp-json/squirrly-seo/v1/assistant[sq_redirect_url][sq_canonical_url][sq_sitemap_url]