All In One SEO Pack for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-all-in-one-seo-pack

Manage All in One SEO Pack meta details for WooCommerce Products within the Add/Edit Products view within the WordPress Administration.

3K active installs v1.3.4 PHP + WP 2.9.2+ Updated Sep 5, 2023
aioseoall-in-one-seo-packwoocommerce-product-seowoocommerce-seo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All In One SEO Pack for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

All In One SEO Pack for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of WooCommerce All-in-One SEO Pack v1.3.4 reveals a generally strong security posture with no identified vulnerabilities in its attack surface or taint flows. The plugin demonstrates good practices by using prepared statements for all SQL queries and performing capability checks. However, a significant concern is the complete lack of output escaping for all 14 identified output points. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted directly without proper sanitization. The vulnerability history shows no known CVEs, which is a positive indicator, suggesting the plugin has historically been well-maintained and secure. Despite the absence of direct vulnerabilities in the analyzed code and history, the widespread lack of output escaping represents a tangible risk that should be addressed to ensure robust security.

Key Concerns

  • All identified outputs are unescaped
Vulnerabilities
None known

All In One SEO Pack for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All In One SEO Pack for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

All In One SEO Pack for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitall-in-one-seo-pack.php:33
actionadmin_noticesincludes\admin.php:19
actionwp_dashboard_setupincludes\common-dashboard_widgets.php:26
actionadd_meta_boxesincludes\functions.php:10
actionwoocommerce_process_product_metaincludes\functions.php:12
actionadmin_initincludes\functions.php:15
Maintenance & Trust

All In One SEO Pack for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedSep 5, 2023
PHP min version
Downloads288K

Community Trust

Rating88/100
Number of ratings14
Active installs3K
Developer Profile

All In One SEO Pack for WooCommerce Developer Profile

Josh Kohlbach

9 plugins · 140K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
849 days
View full developer profile
Detection Fingerprints

How We Detect All In One SEO Pack for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about All In One SEO Pack for WooCommerce