RankWise SEO WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/webcijfers-seo-scan

Contains the SEO core of rankwise.net. Scan the website, individual pages and posts. Contains an authorship check and analyses for Google+ profiles.

20 active installs v2.1.12 PHP + WP 3.3+ Updated Jan 13, 2014
author-rankauthorshipbinggoogleseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RankWise SEO WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

RankWise SEO WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'webcijfers-seo-scan' plugin, version 2.1.12, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and appears to have a very small attack surface with zero identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are correctly using prepared statements, and there are no file operations or external HTTP requests, which are common vectors for exploitation. However, there are significant concerns highlighted by the static code analysis. A complete lack of output escaping across all identified output points (6 total) is a major vulnerability. This means that any data outputted by the plugin is potentially susceptible to Cross-Site Scripting (XSS) attacks if that data originates from or is influenced by user input. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, indicate potential pathways for malicious data injection if not properly handled. The absence of capability checks and nonce checks also raises concerns, as these are fundamental security mechanisms for WordPress plugins to prevent unauthorized actions and verify user intent.

Key Concerns

  • All output is unescaped
  • Unsanitized paths in taint analysis (2 flows)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

RankWise SEO WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RankWise SEO WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
change_rwc (rankwise.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RankWise SEO WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadd_meta_boxesrankwise.php:13
actionadmin_menurankwise.php:14
actiongenesis_footerrankwise.php:23
actiontwentyten_creditsrankwise.php:24
actiontwentythirteen_creditsrankwise.php:25
Maintenance & Trust

RankWise SEO WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 13, 2014
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

RankWise SEO WordPress Plugin Developer Profile

webcijfers

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RankWise SEO WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webcijfers-seo-scan/logoscannow.png

HTML / DOM Fingerprints

CSS Classes
webcijferslogonav-tab-wrappernav-tabnav-tab-activemeterbluemeterinnervulvulmeter
Data Attributes
data-divrel
JS Globals
webcijferstimer
Shortcode Output
<img alt="WebCijfers SEO Scan" height="60" class="wewbcijferslogo" src="
FAQ

Frequently Asked Questions about RankWise SEO WordPress Plugin