SEO Auto Linker Security & Risk Analysis

wordpress.org/plugins/wpa-seo-auto-linker

SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.

4K active installs v1.5.3 PHP + WP 5.6+ Updated Dec 17, 2024
categoriespagespostpoststags
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is SEO Auto Linker Safe to Use in 2026?

Mostly Safe

Score 70/100

SEO Auto Linker is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 1yr ago
Risk Assessment

The "wpa-seo-auto-linker" v1.5.3 plugin generally exhibits good security practices, as indicated by the static analysis. The absence of dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are positive signs. Furthermore, the low number of entry points, all appearing to be protected, and the lack of taint flows suggest a well-secured codebase in its current state. The single external HTTP request and the presence of a nonce check are also commendable.

However, a significant concern arises from the vulnerability history. The plugin has one known medium-severity CVE related to Cross-Site Scripting (XSS) that remains unpatched. This indicates a past vulnerability that has not been remediated, posing a direct risk to users if an exploit for this CVE becomes publicly available or if the vulnerability is still present in this version despite the CVE being recorded for a future date (2025-09-05). The absence of capability checks on any entry points, while the entry points are few, is a potential weakness that could be exploited if an attacker finds a way to trigger these entry points without proper authorization.

In conclusion, while the static analysis paints a picture of a technically sound plugin with good coding habits, the unpatched medium-severity CVE is a critical red flag. The lack of capability checks, although less impactful due to the small attack surface, also warrants attention. The plugin's security posture is therefore compromised by its vulnerability history.

Key Concerns

  • Unpatched CVE (medium severity)
  • 0 capability checks on entry points
Vulnerabilities
1

SEO Auto Linker Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58791medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SEO Auto Linker <= 1.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SEO Auto Linker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
2
46 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

96% escaped48 total outputs
Attack Surface

SEO Auto Linker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterthe_contentwpa-seo-auto-linker.php:20
filtercomment_textwpa-seo-auto-linker.php:22
actioncreate_categorywpa-seo-auto-linker.php:24
actionedit_categorywpa-seo-auto-linker.php:25
actionedit_postwpa-seo-auto-linker.php:26
actionsave_postwpa-seo-auto-linker.php:27
actionadmin_menuwpa-seo-auto-linker.php:28
actionadmin_enqueue_scriptswpa-seo-auto-linker.php:30
actionadmin_enqueue_scriptswpa-seo-auto-linker.php:31
Maintenance & Trust

SEO Auto Linker Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version
Downloads61K

Community Trust

Rating86/100
Number of ratings16
Active installs4K
Developer Profile

SEO Auto Linker Developer Profile

Arjan Olsder

3 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SEO Auto Linker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpa-seo-auto-linker/css/style.css/wp-content/plugins/wpa-seo-auto-linker/js/wpa-seo-auto-linker-admin.js
Script Paths
/wp-content/plugins/wpa-seo-auto-linker/js/wpa-seo-auto-linker-admin.js
Version Parameters
wpa-seo-auto-linker/css/style.css?ver=wpa-seo-auto-linker/js/wpa-seo-auto-linker-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpa-seo-auto-linker-admin-wrap
HTML Comments
<!-- Created by WebsiteNazorg.nl --><!-- Created by WPA SEO Auto Linker -->
JS Globals
SEOAutoLinks
FAQ

Frequently Asked Questions about SEO Auto Linker