Yoast SEO for WordPress PWA Security & Risk Analysis

wordpress.org/plugins/wp-pwa-yoast-seo

Returns Yoast post or page metadata in a normal post or page request.

20 active installs v1.7.0 PHP + WP 4.4+ Updated Feb 7, 2019
seowp-apiwp-pwayoast
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yoast SEO for WordPress PWA Safe to Use in 2026?

Generally Safe

Score 85/100

Yoast SEO for WordPress PWA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'wp-pwa-yoast-seo' v1.7.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the code demonstrates good practices in output escaping and the lack of a vulnerability history suggests a consistent focus on security by the developers.

However, the analysis reveals a complete absence of capability checks and nonce checks. While the current attack surface appears minimal and unprotected entry points are zero, this lack of built-in security mechanisms for potential future expansion or if functionalities are added without careful consideration presents a latent risk. Should any new AJAX handlers or REST API routes be introduced without proper authorization checks, the plugin would be immediately vulnerable.

In conclusion, the plugin is currently very secure due to its minimal complexity and the absence of known vulnerabilities. The primary weakness lies in the foundational lack of explicit authorization checks, which, while not currently exploitable, could become a significant concern if the plugin's functionality or attack surface expands.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Yoast SEO for WordPress PWA Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yoast SEO for WordPress PWA Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Yoast SEO for WordPress PWA Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionrest_api_initplugin.php:15
filterrest_prepare_latestplugin.php:16
actionadmin_noticesplugin.php:113
actionplugins_loadedplugin.php:125
Maintenance & Trust

Yoast SEO for WordPress PWA Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedFeb 7, 2019
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Yoast SEO for WordPress PWA Developer Profile

Pablo Postigo

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yoast SEO for WordPress PWA

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/wp-pwa-yoast-seo/classes/class-wpseo-frontend-to-rest-api.php

HTML / DOM Fingerprints

REST Endpoints
/wp-json/*/yoast_meta
FAQ

Frequently Asked Questions about Yoast SEO for WordPress PWA