
Vinvin SEO Security & Risk Analysis
wordpress.org/plugins/vinvin-seoVinvin SEO is a small extension allow you to add review on page/post. It add review on text also on JSON/LD. Lots of new features incoming
Is Vinvin SEO Safe to Use in 2026?
Generally Safe
Score 85/100Vinvin SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vinvin-seo plugin v2.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also correctly utilizes prepared statements for its SQL queries, which is a significant strength. However, a major concern is the very low percentage of properly escaped output (5%). With 39 total outputs, this indicates that a substantial number of outputs are likely vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks on its entry points (shortcodes) is another significant risk, as it doesn't prevent unauthorized execution of these shortcodes. Despite these concerns, the plugin has no recorded vulnerabilities, which suggests that either existing vulnerabilities have been patched, or the plugin's limited functionality and attack surface haven't been heavily targeted or exploited in the past. The strong adherence to prepared statements is a positive indicator of secure coding practices in database interactions. However, the output escaping and nonce check deficiencies represent significant areas of risk that require immediate attention. In conclusion, while the plugin demonstrates strengths in database security, its handling of user-provided data and request verification presents notable vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on shortcodes
Vinvin SEO Security Vulnerabilities
Vinvin SEO Code Analysis
Output Escaping
Data Flow Analysis
Vinvin SEO Attack Surface
Shortcodes 4
WordPress Hooks 9
Maintenance & Trust
Vinvin SEO Maintenance & Trust
Maintenance Signals
Community Trust
Vinvin SEO Alternatives
No alternatives data available yet.
Vinvin SEO Developer Profile
4 plugins · 810 total installs
How We Detect Vinvin SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vinvin-seo/vinvin.css/wp-content/plugins/vinvin-seo/vinvin.jsvinvin-seo/vinvin.css?ver=vinvin-seo/vinvin.js?ver=HTML / DOM Fingerprints
v_id_post<!-- Ajout d'un param pour disable BHM --><!-- Antidaté les post -->id="v_id_post"window.vinvin_seo_options