
WP Keywords Report Security & Risk Analysis
wordpress.org/plugins/wp-keywords-reportKnow your blog position in Google SERP
Is WP Keywords Report Safe to Use in 2026?
Generally Safe
Score 85/100WP Keywords Report has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-keywords-report' plugin v1.0 exhibits a generally positive security posture based on the provided static analysis, with no identified dangerous functions, file operations, or external HTTP requests. Notably, all SQL queries utilize prepared statements, which is an excellent practice for preventing SQL injection vulnerabilities. The absence of any recorded vulnerabilities in its history further suggests a commitment to security or simply a lack of past exploitable issues.
However, there are significant concerns regarding output escaping. With three total outputs and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or external sources and is not properly escaped can be exploited by attackers to inject malicious scripts. Additionally, the complete lack of nonce checks and capability checks across all entry points (even though there are none identified) is a red flag. If entry points were to be discovered or added in future versions, the absence of these fundamental security controls would leave them unprotected.
In conclusion, while the plugin has strengths in its handling of SQL and its clean vulnerability history, the critical weakness in output escaping presents a substantial risk. The lack of authentication and authorization checks on potential future entry points is also a concern that needs to be addressed. The current score reflects these critical issues despite the absence of known CVEs.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
WP Keywords Report Security Vulnerabilities
WP Keywords Report Code Analysis
Output Escaping
WP Keywords Report Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Keywords Report Maintenance & Trust
Maintenance Signals
Community Trust
WP Keywords Report Alternatives
SEO Stats Widget
seo-stats-widget
Display SEO Statistics of blog
Custom Sitemap Generator
custom-sitemap-generator
The most powerful standalone XML sitemap generator for WordPress with support for all post types, taxonomies, authors, and advanced SEO features.
Vibe SEO Pack
vibe-seo-pack
Vibe SEO Pack is a simple powerful and easy to use SEO tool to optimize your website for search engines without having to edit a single line of code.
SEO Recipe Snippets
recipe-snippets
Show recipe snippets on Google search results.
SEO Content Control
seo-content-control
SEO Content Control helps to identify and clean up various sorts of weak content, in order to improve a site's quality and to rank better.
WP Keywords Report Developer Profile
7 plugins · 270 total installs
How We Detect WP Keywords Report
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
gkr<div class="gkr"><table class="gkr"><thead><tr><th>Keyword</th><th>URL</th><th>Position</th><th>Traffic</th><th>keyword Cost</th><th>Queries/Day</th><th>Results in Google</th></tr></thead><tbody><td>