Top Image SEO Security & Risk Analysis

wordpress.org/plugins/woo-image-seo

Improve your WooCommerce SEO! Automatically add alt tags and title attributes to product images using Top Image SEO.

5K active installs v1.5.0 PHP 7.0+ WP 4.1+ Updated Nov 29, 2025
product-altproduct-seowoowoo-seowoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Top Image SEO Safe to Use in 2026?

Generally Safe

Score 100/100

Top Image SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'woo-image-seo' plugin version 1.5.0 exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a lack of dangerous functions, proper SQL query sanitization, file operations, external HTTP requests, and the absence of bundled libraries. This suggests that the developers have taken steps to avoid common vulnerability vectors.

However, a significant concern arises from the output escaping data, which shows that 0% of the 28 total outputs are properly escaped. This is a critical weakness as it leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Any dynamic content generated by the plugin that is not properly escaped could be manipulated by an attacker to inject malicious scripts, which could then be executed in the user's browser. The lack of nonce and capability checks on potential entry points, although the entry points are currently zero, also represents a potential risk if new functionalities with entry points are added without proper security considerations.

Historically, the plugin has no recorded vulnerabilities, which is an excellent sign. This indicates a track record of secure development. However, the current lack of output escaping presents a significant and immediate risk that overshadows the historical good performance. While the attack surface is minimal and SQL queries are prepared, the complete failure to escape output poses a critical XSS vulnerability. The plugin's strengths lie in its limited attack surface and secure database interactions, but its weakness in output sanitization demands immediate attention.

Key Concerns

  • 0% of outputs properly escaped
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

Top Image SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Top Image SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped28 total outputs
Attack Surface

Top Image SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionbefore_woocommerce_initwoo-image-seo.php:24
Maintenance & Trust

Top Image SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 29, 2025
PHP min version7.0
Downloads92K

Community Trust

Rating98/100
Number of ratings27
Active installs5K
Developer Profile

Top Image SEO Developer Profile

emandiev

4 plugins · 5K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Top Image SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-image-seo/public/css/frontend.css/wp-content/plugins/woo-image-seo/public/js/frontend.js
Version Parameters
woo-image-seo/public/css/frontend.css?ver=woo-image-seo/public/js/frontend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Top Image SEO