WP API Yoast SEO Security & Risk Analysis

wordpress.org/plugins/wp-api-yoast-meta

Returns Yoast post or page metadata in a normal post or page request.

600 active installs v1.2.0 PHP + WP 4.4+ Updated Jul 29, 2016
restseowp-apiyoast
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP API Yoast SEO Safe to Use in 2026?

Generally Safe

Score 85/100

WP API Yoast SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The wp-api-yoast-meta v1.2.0 plugin demonstrates an exceptionally strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, SQL queries not using prepared statements, unescaped output, file operations, external HTTP requests, nonce checks, and capability checks is a significant positive indicator. The plugin also has zero known CVEs, indicating a lack of past security incidents.

However, the analysis also reveals an alarmingly small attack surface. With zero AJAX handlers, REST API routes, shortcodes, and cron events, it's difficult to definitively assess the plugin's overall security. The lack of these common entry points means that many potential security vulnerabilities, such as those related to input validation or authorization, might not have been detectable through this specific static analysis. The total absence of taint analysis flows also raises a question about the thoroughness of that particular aspect of the security review, or it might simply reflect the plugin's minimal functionality.

In conclusion, while the plugin's code appears robust and free from common vulnerabilities based on the reported metrics, the minimal attack surface makes it challenging to provide a comprehensive risk assessment. The lack of recorded vulnerabilities is excellent, but the extremely limited interaction points could mean that potential risks are simply not exposed or detectable by this analysis. A more extensive code review or dynamic analysis might be beneficial for a complete understanding of its security.

Vulnerabilities
None known

WP API Yoast SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP API Yoast SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP API Yoast SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionrest_api_initplugin.php:14
Maintenance & Trust

WP API Yoast SEO Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJul 29, 2016
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

WP API Yoast SEO Developer Profile

ChazUK

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP API Yoast SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wp-api-yoast-meta
FAQ

Frequently Asked Questions about WP API Yoast SEO