
WP Dynamic Keywords Injector Security & Risk Analysis
wordpress.org/plugins/wp-dynamic-keywords-injectorWP Dynamic Keywords Injector inserts dynamic keywords, spintax, page title and title tag.
Is WP Dynamic Keywords Injector Safe to Use in 2026?
Generally Safe
Score 99/100WP Dynamic Keywords Injector has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-dynamic-keywords-injector" plugin v2.3.27 demonstrates a generally strong security posture with several positive indicators. The absence of unpatched CVEs, raw SQL queries, and critical or high severity taint flows is commendable. The plugin also employs nonce checks on its AJAX handlers, which is a good practice for preventing CSRF attacks. The majority of output is properly escaped, mitigating XSS risks.
However, there are areas of concern. The presence of one flow with an unsanitized path, even if not flagged as critical or high, warrants investigation as it could potentially lead to security vulnerabilities if not properly handled. Furthermore, the lack of capability checks on AJAX handlers is a significant weakness. While nonces prevent unauthorized *users* from triggering actions, they do not prevent *logged-in* users with insufficient privileges from doing so. The plugin's vulnerability history, which includes medium severity XSS and CSRF vulnerabilities, suggests a past tendency towards these types of issues, highlighting the importance of continued vigilance.
In conclusion, while the plugin has made strides in security with its current version, the lack of capability checks on AJAX handlers and the presence of a potentially unsanitized path represent notable risks. The past vulnerability history also suggests that a thorough review of input validation and output escaping, particularly concerning user-controllable data, is still crucial.
Key Concerns
- AJAX handlers lack capability checks
- Flow with unsanitized path identified
- Past medium severity vulnerabilities (XSS, CSRF)
- Some output not properly escaped
WP Dynamic Keywords Injector Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Dynamic Keywords Injector <= 2.3.21 - Reflected Cross-Site Scripting
WP Dynamic Keywords Injector <= 2.3.15 - Cross-Site Request Forgery
WP Dynamic Keywords Injector Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WP Dynamic Keywords Injector Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
WP Dynamic Keywords Injector Maintenance & Trust
Maintenance Signals
Community Trust
WP Dynamic Keywords Injector Alternatives
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
Simple SEO by falbar
simple-seo-by-falbar
This plugin extends the standard SEO WordPress features.
WP Custom Category Meta
wp-custom-category-meta
Allow you to add custom meta tags and title for category.
Dynamic URL SEO
dynamic-url-seo
This plugin is used to add meta title, keywords and description for dynamic URLs which are not available in database.
Simple Current Date Time
simple-current-date-time
Simple plugin for current, localized dates & times via shortcodes. Use in content, H1 & SEO titles. Lightweight.
WP Dynamic Keywords Injector Developer Profile
4 plugins · 1K total installs
How We Detect WP Dynamic Keywords Injector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-dynamic-keywords-injector/js/jquery.magnific-popup.min.js/wp-content/plugins/wp-dynamic-keywords-injector/css/magnific-popup.min.css/wp-content/plugins/wp-dynamic-keywords-injector/js/jquery.magnific-popup.min.jswp-dynamic-keywords-injector/style.css?ver=HTML / DOM Fingerprints
seerox-wpdkidata-srx-popup-iddata-srx-titlesrx_popup_opensrx_add_popup_option[seerox_wpdki_dyn_keywords][seerox_wpdki_dyn_keywords spintax=