WP SEO Title Security & Risk Analysis

wordpress.org/plugins/wp-seo-title

This SEO plugin offers keyword suggestions with Volume, CPC and Profit

10 active installs v1.0.2 PHP + WP 3.0+ Updated Apr 2, 2015
keywordsseotitle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP SEO Title Safe to Use in 2026?

Generally Safe

Score 85/100

WP SEO Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wp-seo-title" v1.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and includes nonce checks. The absence of known vulnerabilities and CVEs in its history is also a strong indicator of past diligence. However, significant concerns arise from the static analysis. The presence of one AJAX handler without authentication is a critical vulnerability. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a potential for sensitive data to be manipulated or exposed. While the number of these unsanitized paths is small, their existence, combined with the unprotected AJAX endpoint, creates a notable attack vector that could be exploited.

Key Concerns

  • AJAX handler without authentication
  • Taint flows with unsanitized paths
  • Output escaping 56% properly escaped
Vulnerabilities
None known

WP SEO Title Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP SEO Title Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
10 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

56% escaped18 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
ajax_title_suggestions (wp-seo-title.php:89)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WP SEO Title Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wpst_title_suggestionswp-seo-title.php:20
WordPress Hooks 2
actionadmin_menuwp-seo-title.php:18
actionadmin_initwp-seo-title.php:19
Maintenance & Trust

WP SEO Title Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 2, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP SEO Title Developer Profile

Nicolas Marin Torres

2 plugins · 610 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP SEO Title

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-seo-title/js/wp-seo-title.js/wp-content/plugins/wp-seo-title/js/jquery.gcomplete.0.1.2.js/wp-content/plugins/wp-seo-title/js/jquery.ddslick.min.js/wp-content/plugins/wp-seo-title/css/wp-seo-title.css/wp-content/plugins/wp-seo-title/css/jquery.gcomplete.default-themes.css
Script Paths
/wp-content/plugins/wp-seo-title/js/wp-seo-title.js/wp-content/plugins/wp-seo-title/js/jquery.gcomplete.0.1.2.js/wp-content/plugins/wp-seo-title/js/jquery.ddslick.min.js
Version Parameters
wp-seo-title.js?ver=jquery.gcomplete.0.1.2.js?ver=jquery.ddslick.min.js?ver=wp-seo-title.css?ver=jquery.gcomplete.default-themes.css?ver=

HTML / DOM Fingerprints

HTML Comments
comentario /* BETA */
Data Attributes
data-imagesrcdata-description
JS Globals
objectL10nWPST
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about WP SEO Title