
XYZZY Basic SEO & Analytics Security & Risk Analysis
wordpress.org/plugins/xyzzy-basic-seo-analyticsXYZZY Basic SEO & Analytics es un sencillo y ligero plugin con el que integrar Analytics y los metadatos SEO en nuestra web.
Is XYZZY Basic SEO & Analytics Safe to Use in 2026?
Generally Safe
Score 85/100XYZZY Basic SEO & Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "xyzzy-basic-seo-analytics" v1.0.5 plugin presents a mixed security posture. On the positive side, the plugin exhibits a commendably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks. Furthermore, all SQL queries are properly prepared, and there are no known historical vulnerabilities (CVEs) associated with this plugin, indicating a potentially stable development history.
However, there are significant areas of concern within the static analysis. A mere 15% of output escaping is a critical weakness. This means that a substantial amount of user-supplied or dynamically generated data is likely being rendered directly into the browser without proper sanitization, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also reveals two flows with unsanitized paths, although thankfully these are not currently classified as critical or high severity. The complete absence of nonce checks is also a notable concern, especially in conjunction with the limited capability checks and the potential for XSS. While the attack surface is small, the lack of robust output escaping is the most pressing issue, leaving it vulnerable to client-side attacks.
Key Concerns
- Insufficient output escaping (15%)
- Unsanitized paths in taint flows (2)
- No nonce checks
XYZZY Basic SEO & Analytics Security Vulnerabilities
XYZZY Basic SEO & Analytics Code Analysis
Output Escaping
Data Flow Analysis
XYZZY Basic SEO & Analytics Attack Surface
WordPress Hooks 9
Maintenance & Trust
XYZZY Basic SEO & Analytics Maintenance & Trust
Maintenance Signals
Community Trust
XYZZY Basic SEO & Analytics Alternatives
SEO SIMPLE PACK
seo-simple-pack
This is a very simple SEO plugin. You can easily set and customize meta tags and OGP tags for each page.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Website Optimization – Plerdy
plerdy-heatmap
Optimize your website with Plerdy by analyzing traffic sources, scroll depth, user clicks, and usability to enhance conversion and strategy.
SEO Engine
seo-engine
Made it through the SEO plugin wasteland? You've earned a coffee ☺️ Quietly powerful AI SEO that actually works. No bloat, just results. Enjoy! 💕
ShinyStat Analytics
shinystat-analytics
Plugin to activate the ShinyStat Analytics services on your website.
XYZZY Basic SEO & Analytics Developer Profile
1 plugin · 20 total installs
How We Detect XYZZY Basic SEO & Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xyzzy-basic-seo-analytics/admin/js/token-form.js/wp-content/plugins/xyzzy-basic-seo-analytics/admin/css/xbs-admin-styles.css/wp-content/plugins/xyzzy-basic-seo-analytics/admin/js/token-form.jsxyzzy-basic-seo-analytics/admin/js/token-form.js?ver=xyzzy-basic-seo-analytics/admin/css/xbs-admin-styles.css?ver=HTML / DOM Fingerprints
<!-- XYZZY Basic SEO meta tags --><!-- End XYZZY Basic SEO meta tags -->data-block="editor"data-editor="editor"data-editor-theme="theme"data-editor-content="content"data-components="components"data-wp-edit-post="edit-post"window.wp.datawindow.wp.componentswindow.wp.domReadywindow.wp.i18nwindow.wp.compose/wp-json/wp/v2/posts