WPSSO Core – Complete Schema Markup and Meta Tags Security & Risk Analysis

wordpress.org/plugins/wpsso

Present your content at its best for social sites and search results, no matter how URLs are shared, reshared, messaged, posted, embedded, or crawled.

5K active installs v21.13.1 PHP 7.4.33+ WP 6.0+ Updated Apr 15, 2026
meta-tagsoptimizeschemasearch-resultswoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 30, 2024
Safety Verdict

Is WPSSO Core – Complete Schema Markup and Meta Tags Safe to Use in 2026?

Generally Safe

Score 99/100

WPSSO Core – Complete Schema Markup and Meta Tags has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 30, 2024Updated 1mo ago
Risk Assessment

The static analysis of wpsso v21.11.2 reveals a generally strong security posture, with no identified attack surface points like AJAX handlers, REST API routes, or shortcodes. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths suggests a well-secured codebase. The plugin also demonstrates good practices by using prepared statements for all SQL queries. However, a significant concern arises from the complete lack of output escaping. With one output identified and none properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the output without proper sanitization.

The vulnerability history shows one known CVE, which is now patched, indicating that past issues have been addressed. The absence of critical or high severity CVEs in the past is positive. However, the presence of a past medium severity vulnerability, specifically related to 'Missing Authorization,' is a noteworthy pattern. While this specific vulnerability is no longer present, it highlights a potential area of weakness that needs continuous vigilance. The lack of nonce and capability checks further contributes to the overall risk, as these are fundamental security mechanisms for WordPress plugins.

In conclusion, wpsso v21.11.2 exhibits strengths in its limited attack surface and secure SQL handling. Nevertheless, the critical oversight in output escaping, combined with the historical pattern of authorization issues and the absence of common WordPress security checks like nonces and capability checks, creates significant security risks. The lack of proper output escaping is the most immediate and severe concern that needs to be addressed.

Key Concerns

  • Unescaped output detected
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
1 published

WPSSO Core – Complete Schema Markup and Meta Tags Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-56243medium · 4.3Missing Authorization

WPSSO Core <= 18.18.1 - Missing Authorization

Dec 30, 2024 Patched in 18.18.2 (10d)
Version History

WPSSO Core – Complete Schema Markup and Meta Tags Release Timeline

v21.13.1Current
v21.12.0
Code Analysis
Analyzed Mar 16, 2026

WPSSO Core – Complete Schema Markup and Meta Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

WPSSO Core – Complete Schema Markup and Meta Tags Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitwpsso.php:112
actionwidgets_initwpsso.php:113
actioninitwpsso.php:114
actioninitwpsso.php:115
actioninitwpsso.php:116
actioninitwpsso.php:117
actionwpsso_init_textdomainwpsso.php:122
actionchange_localewpsso.php:127
filterload_textdomain_mofilewpsso.php:132
actionbefore_woocommerce_initwpsso.php:141
Maintenance & Trust

WPSSO Core – Complete Schema Markup and Meta Tags Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.4.33
Downloads4.1M

Community Trust

Rating92/100
Number of ratings306
Active installs5K
Developer Profile

WPSSO Core – Complete Schema Markup and Meta Tags Developer Profile

JS Morisset

31 plugins · 32K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect WPSSO Core – Complete Schema Markup and Meta Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpsso/css/wpsso-admin.css/wp-content/plugins/wpsso/css/wpsso-core.css/wp-content/plugins/wpsso/css/wpsso-styles.css/wp-content/plugins/wpsso/js/wpsso-admin.js/wp-content/plugins/wpsso/js/wpsso-core.js/wp-content/plugins/wpsso/js/wpsso-script.js
Generator Patterns
WPSSO Core
Script Paths
/wp-content/plugins/wpsso/js/wpsso-admin.js/wp-content/plugins/wpsso/js/wpsso-core.js/wp-content/plugins/wpsso/js/wpsso-script.js
Version Parameters
wpsso/css/wpsso-admin.css?ver=wpsso/css/wpsso-core.css?ver=wpsso/css/wpsso-styles.css?ver=wpsso/js/wpsso-admin.js?ver=wpsso/js/wpsso-core.js?ver=wpsso/js/wpsso-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpsso_meta_boxwpsso_admin_notice
HTML Comments
<!-- WPSSOWPSSO Filtered By
Data Attributes
data-wpsso-actiondata-wpsso-nonce
JS Globals
window.wpsso_noncewindow.wpsso_admin_ajax_url
REST Endpoints
/wp-json/wpsso/v1
FAQ

Frequently Asked Questions about WPSSO Core – Complete Schema Markup and Meta Tags