{"id":344577,"date":"2026-08-30T11:52:48","date_gmt":"2026-08-30T11:52:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/nxsite-seo-audit\/"},"modified":"2026-08-30T21:08:26","modified_gmt":"2026-08-30T21:08:26","slug":"nx-site-seo-audit","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/nx-site-seo-audit\/","author":23528879,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"5.3.0","stable_tag":"5.3.0","tested":"7.0.4","requires":"5.8","requires_php":"7.4.3","requires_plugins":null,"header_name":"NX::Site SEO Audit","header_author":"NETSOLEX","header_description":"Complete SEO & Content Audit Tool - Meta Tags, Headings, Images, Links, Content Analysis, Sitemap Generator & More","assets_banners_color":"053073","last_updated":"2026-08-30 21:08:26","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.netsolex.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":29,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"5.3.0":{"tag":"5.3.0","author":"netsolex","date":"2026-08-30 21:08:26","revision":3673126}},"upgrade_notice":{"5.3.0":"<p>Compliance update: the CSS\/JS Minify tool no longer accepts free-typed\/pasted code, only real files already on your site. Recommended update for all users.<\/p>","5.2.0":"<p>Important: the wp-config.php code editor has been removed for WordPress.org compliance. If you have any pending performance defines or table-prefix rename to apply, use the new &quot;copy code&quot; buttons and paste them into wp-config.php yourself.<\/p>","5.1.8":"<p>Security update: SMTP password is now encrypted at rest, and SSRF protection was added to the Minify Analyzer endpoints. Update recommended for all users.<\/p>","5.1.7":"<p>Important bug fix: the SEO Title from NX Meta Generator was not being output as a `` tag on the live page. Update immediately to ensure your custom titles are active on the frontend.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3672478,"resolution":"128x128","location":"assets","locale":"","width":256,"height":256},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3672478,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3672478,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3672478,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["5.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3672478,"resolution":"1","location":"assets","locale":"","width":455,"height":1476},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3672478,"resolution":"2","location":"assets","locale":"","width":455,"height":659},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3672478,"resolution":"3","location":"assets","locale":"","width":455,"height":2541},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3672478,"resolution":"4","location":"assets","locale":"","width":455,"height":936},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3672478,"resolution":"5","location":"assets","locale":"","width":455,"height":448},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3672478,"resolution":"6","location":"assets","locale":"","width":445,"height":1388}},"screenshots":{"1":"Dashboard \u2014 Global SEO Score, issue summary, and page status overview.","2":"Audit View \u2014 Per-page issue breakdown with severity levels.","3":"Security Tools \u2014 XML-RPC, .htaccess, robots.txt, and file permissions management.","4":"DB Optimizer \u2014 Database cleanup with row counts before confirmation.","5":"Backup &amp; Restore \u2014 Full database backup and restore panel.","6":"Image Converter \u2014 Batch WebP conversion from the Media Library."}},"plugin_section":[],"plugin_tags":[8533,151,600,186,1557],"plugin_category":[54,55,59],"plugin_contributors":[278319,278318],"plugin_business_model":[],"class_list":["post-344577","plugin","type-plugin","status-publish","hentry","plugin_tags-audit","plugin_tags-backup","plugin_tags-security","plugin_tags-seo","plugin_tags-sitemap","plugin_category-security-and-spam-protection","plugin_category-seo-and-marketing","plugin_category-utilities-and-tools","plugin_contributors-gaichenya","plugin_contributors-netsolex","plugin_committers-netsolex"],"banners":{"banner":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/banner-772x250.png?rev=3672478","banner_2x":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/banner-1544x500.png?rev=3672478","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/icon-128x128.png?rev=3672478","icon_2x":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/icon-256x256.png?rev=3672478","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-1.png?rev=3672478","caption":"Dashboard \u2014 Global SEO Score, issue summary, and page status overview."},{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-2.png?rev=3672478","caption":"Audit View \u2014 Per-page issue breakdown with severity levels."},{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-3.png?rev=3672478","caption":"Security Tools \u2014 XML-RPC, .htaccess, robots.txt, and file permissions management."},{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-4.png?rev=3672478","caption":"DB Optimizer \u2014 Database cleanup with row counts before confirmation."},{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-5.png?rev=3672478","caption":"Backup &amp; Restore \u2014 Full database backup and restore panel."},{"src":"https:\/\/ps.w.org\/nx-site-seo-audit\/assets\/screenshot-6.png?rev=3672478","caption":"Image Converter \u2014 Batch WebP conversion from the Media Library."}],"raw_content":"<!--section=description-->\n<p>NX::Site SEO Audit is a professional, all-in-one SEO and site health toolkit for WordPress. With a global SEO Site Score (0\u2013100), page-by-page status classification, advanced DB Optimizer, Security Tools, full database Backup &amp; Restore, CSS\/JS Minification Analyzer, multilingual support in 6 languages, and automatic email notifications for new critical issues.<\/p>\n\n<p>Developed by NETSOLEX \u2014 https:\/\/www.netsolex.com<\/p>\n\n<h3>Core Features<\/h3>\n\nDashboard &amp; SEO Score.\n\n<p>A unified control panel showing your global SEO Site Score (0\u2013100), categorised issue counts (Critical, Warning, Info), recent audit history, and a full page-by-page status overview. At a glance you know which pages are healthy, which need improvement, and which have critical problems.<\/p>\n\nMeta Tags Analyzer.\n\n<p>Audit every post and page for title tags, meta descriptions, Open Graph tags (og:title, og:description, og:image, og:type), Twitter Cards, canonical URLs, robots meta directives (index\/noindex\/follow\/nofollow), and Schema.org structured data. Highlights missing or duplicate entries immediately.<\/p>\n\nNX Meta Generator.\n\n<p>A per-page custom meta tag generator accessible directly from the post\/page list. Lets you define:\n* SEO Title (injected as <code>&lt;title&gt;<\/code> tag and used via WordPress <code>pre_get_document_title<\/code> filter)\n* Meta Description\n* Robots directives (index\/noindex, follow\/nofollow)\n* Open Graph title, description, and image\n* Twitter Card title, description, and image\n* Schema.org type (Organization, Article, Product, LocalBusiness, etc.)\n* Viewport, theme-color, revisit-after, language, googlebot, bingbot\n* Canonical URL\n* Article published\/modified dates\n* Facebook publisher URL<\/p>\n\n<p>The generator produces a live HTML preview in the editor and injects all tags directly into the page <code>&lt;head&gt;<\/code> on the frontend. Includes a full-screen editor mode (<code>nxmeta_edit<\/code>) for a distraction-free workflow.<\/p>\n\nHeadings Structure (H1\u2013H6).\n\n<p>Analyses the heading hierarchy of every post and page. Detects missing H1 tags, multiple H1s on the same page, skipped heading levels, and empty headings. Helps ensure your content structure is accessible and SEO-friendly.<\/p>\n\nImages Audit.\n\n<p>Scans all images across your site for missing or empty ALT text, decorative images without <code>alt=\"\"<\/code>, oversized images, missing lazy-load attributes, and non-WebP formats. Displays full image URL, context, and post title per finding.<\/p>\n\nLinks Analysis.\n\n<p>Crawls internal and external links on every post and page. Detects broken links (404, 5xx), redirected links, missing <code>rel<\/code> attributes, and nofollow patterns. Supports a configurable allowlist to exclude known external domains from reporting.<\/p>\n\nContent Analysis.\n\n<p>Evaluates content quality page by page: word count, readability, thin content detection (configurable minimum word count), and duplicate or near-duplicate paragraphs. Configurable thresholds for minimum word count, title length, and description length.<\/p>\n\nKeywords Analysis.\n\n<p>Extracts and ranks keywords by frequency across all audited posts and pages. Identifies keyword density, over-optimised content, and missing focus keywords.<\/p>\n\nKeyword Cannibalization Detector.\n\n<p>Identifies groups of pages competing for the same keyword, which can split ranking authority and confuse search engines. Helps you decide which page to consolidate, redirect, or mark canonical.<\/p>\n\nDuplicate Content Detector.\n\n<p>Compares content across posts and pages using similarity algorithms. Flags pages with a high content similarity score so you can consolidate or differentiate them.<\/p>\n\nInternal Link Graph.\n\n<p>Visualises the internal linking structure of your site as an interactive node graph. Identify orphan pages (no internal links pointing to them), over-linked pages, and link clusters.<\/p>\n\nImage Converter (WebP).\n\n<p>Converts existing JPEG and PNG images in your Media Library to WebP format directly from the WordPress admin. Reduces file sizes significantly without quality loss, improving Core Web Vitals.<\/p>\n\nSEO Recommendations (SEO Tips).\n\n<p>A curated list of actionable SEO tips and best practices, organised by priority. Helps less technical users understand what improvements to make and why.<\/p>\n\nTechnical SEO.\n\n<p>Covers technical health checks including: robots.txt validation, XML sitemap presence, HTTPS enforcement, redirect chains, canonical conflicts, and page speed indicators.<\/p>\n\nReports &amp; Export.\n\n<p>Generate and download audit reports in CSV or PDF format. Export full issue lists, per-page breakdowns, and summary dashboards for clients or team review.<\/p>\n\nSitemap Generator (XML).\n\n<p>Automatically generates and updates an XML sitemap for posts, pages, and custom post types. Configurable priorities and change frequencies.<\/p>\n\nDB Optimizer.\n\n<p>A powerful database maintenance tool that cleans: post revisions, auto-draft posts, trashed posts, transients (expired and all), orphaned post meta, comment meta, spam comments, and more. All operations are listed with row counts before you confirm. Supports WP-Cron automation for scheduled cleanups.<\/p>\n\nMinify Analyzer.\n\n<p>Analyses your site's CSS and JS assets for minification opportunities. Lists all enqueued scripts and styles with their sizes, minification status, and potential savings.<\/p>\n\nSecurity &amp; SEO Tools.\n\n<p>XML-RPC Security \u2014 Disable XML-RPC completely to block DDoS amplification attacks, brute-force via pingbacks, and remote publishing exploits.\n.htaccess File Management \u2014 View, edit, and save your <code>.htaccess<\/code> file directly from the admin. Create a new one from defaults if it is missing.\nrobots.txt File Management \u2014 View, edit, optimise, and save your <code>robots.txt<\/code>. Load default templates or add your sitemap reference automatically.\nwp-config.php File Management \u2014 Read and edit <code>wp-config.php<\/code> with built-in safeguards.\nFile Permissions Manager \u2014 View and set correct file\/folder permissions (755\/644) for all WordPress core paths.\nForce HTTPS \u2014 One-click redirect to enforce HTTPS site-wide via <code>.htaccess<\/code>.\nSitemap in robots.txt \u2014 Automatically append the sitemap URL to your <code>robots.txt<\/code>.<\/p>\n\nBackup &amp; Restore.\n\n<p>Full database backup to a downloadable SQL file. Restore from a previously downloaded backup. Backups are stored in a protected uploads directory (with <code>.htaccess<\/code> and <code>index.php<\/code> guards).<\/p>\n\nNX Plugin Administrator.\n\n<p>A password-protected admin area within the plugin for managing advanced settings, rate limiting, and access control. Separate from the standard WordPress admin role system.<\/p>\n\nEmail Notifications &amp; SMTP.\n\n<p>Configure automatic email alerts when new critical SEO issues are detected. Supports custom SMTP configuration (host, port, TLS\/SSL, authentication, from name\/email) for reliable delivery.<\/p>\n\nSettings.\n\n<p>Configurable options include:\n* Post types to audit (posts, pages, custom post types)\n* Minimum word count threshold\n* Maximum title length (default 60 characters)\n* Maximum description length (default 160 characters)\n* Audit batch limit\n* Items per page for each module\n* Plugin language\n* Email notification address\n* SMTP configuration\n* Link allowlist\n* WebP, lazy-load, and image dimension checks\n* Show\/hide developer badge on the frontend\n* Delete plugin tables on deactivation<\/p>\n\n<p><strong>Multilingual Support<\/strong>\nThe plugin interface is fully translated into:\n* English (default)\n* Spanish (es_ES)\n* German (de_DE)\n* French (fr_FR)\n* Italian (it_IT)\n* Portuguese (pt_PT)<\/p>\n\n<p>Language is selectable from the plugin Settings page, independently of the WordPress site language.<\/p>\n\n\n\n<h3>System Requirements<\/h3>\n\n<p>WordPress: 5.8 or higher (tested up to 7.0)\nPHP: 7.4.3 or higher (PHP 8.3+ recommended)\nMySQL \/ MariaDB: 5.6 or higher\nWeb Server: Apache (fully tested and supported). NGINX not tested \u2014 <code>.htaccess<\/code>-dependent features will not function on NGINX.\nBrowser: Any modern browser (Chrome, Firefox, Brave, Edge)\nSSL: Recommended. The Force HTTPS feature requires an active SSL certificate.<\/p>\n\nPage Builder Compatibility:\n\n<p>\u2705 YOOtheme \u2014 Tested and confirmed working\n* Elementor \u2014 Not yet tested\n* WPBakery \u2014 Not yet tested\n* Divi \u2014 Not yet tested<\/p>\n\n<h3>Privacy Policy &amp; External Services<\/h3>\n\n<p>This plugin connects to external services in the following specific cases. All connections are either triggered explicitly by the user or are necessary for a core feature to work. No data is ever collected automatically in the background without user action.<\/p>\n\n<ol>\n<li>License Registration (voluntary \u2014 only when user submits the form)<\/li>\n<\/ol>\n\n<p>When a user fills in and submits the License Registration form (Plugins \u2192 Site SEO Audit \u2192 License), the following data is sent to the NETSOLEX license server at <strong>https:\/\/www.netsolex.com\/api\/nxsa\/register\/<\/strong>:<\/p>\n\n<ul>\n<li>Site domain (e.g. example.com)<\/li>\n<li>Email address entered by the user<\/li>\n<li>Name entered by the user (optional)<\/li>\n<li>Plugin name and version number<\/li>\n<li>A generated license key<\/li>\n<\/ul>\n\n<p>This request is non-blocking \u2014 it does not slow down the page. No data is sent unless the user actively clicks the Register button.\nThe data is used solely to validate and record the license.\nNETSOLEX Terms of Service: https:\/\/www.netsolex.com\/terms-of-service\/\nNETSOLEX Privacy Policy: https:\/\/www.netsolex.com\/privacy-policy\/<\/p>\n\n<ol>\n<li>Plugin Update Checks (automatic \u2014 admin area only)<\/li>\n<\/ol>\n\n<p>When a WordPress administrator visits the Plugins page or the Dashboard, WordPress performs its standard update check. This plugin participates in that check by contacting the NETSOLEX update API to verify whether a new version is available. The request includes the current plugin version and the site URL \u2014 no personal data is sent. This is standard WordPress plugin behaviour.\nNETSOLEX Terms of Service: https:\/\/www.netsolex.com\/terms-of-service\/\nNETSOLEX Privacy Policy: https:\/\/www.netsolex.com\/privacy-policy\/<\/p>\n\n<ol>\n<li>Sitemap Ping (automatic \u2014 only when sitemap is generated)<\/li>\n<\/ol>\n\n<p>When an XML sitemap is generated or updated, the plugin sends a ping notification to <strong>https:\/\/www.google.com\/ping<\/strong> and <strong>https:\/\/www.bing.com\/ping<\/strong> with the public URL of your sitemap. This is standard search engine notification behaviour. No personal data is included.\nGoogle Privacy Policy: https:\/\/policies.google.com\/privacy\nMicrosoft\/Bing Privacy Statement: https:\/\/privacy.microsoft.com\/privacystatement<\/p>\n\n<ol>\n<li>External CSS\/JS Asset Fetching (on-demand \u2014 admin only)<\/li>\n<\/ol>\n\n<p>The Minify Analyzer fetches CSS and JS files from URLs already present on your site in order to analyse their minification status. These are requests to your own site assets or to public CDN URLs already loaded by your theme or plugins. No data is sent to NETSOLEX.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Download the plugin ZIP file.<\/li>\n<li>In your WordPress admin go to Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Choose the ZIP file and click Install Now.<\/li>\n<li>After installation click Activate Plugin.<\/li>\n<li>Navigate to Site SEO Audit in the left admin menu to start your first audit.<\/li>\n<\/ol>\n\n<p>Alternatively, install via FTP by uploading the <code>nx-site-seo-audit<\/code> folder to <code>\/wp-content\/plugins\/<\/code> and activating from <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20work%20with%20page%20builders%3F\"><h3>Does this plugin work with page builders?<\/h3><\/dt>\n<dd><p>YOOtheme \u2014 Tested and fully compatible.\nElementor \u2014 Not yet formally tested. The plugin operates at the WordPress core level (hooks and meta), so it should work in most cases, but compatibility is not officially guaranteed.\nWPBakery (Visual Composer) \u2014 Not yet formally tested. Same considerations as Elementor apply.\nDivi \u2014 Not yet formally tested. Same considerations as Elementor apply.<\/p>\n\n<p>If you use one of the above builders and encounter issues, please report via the support tab.<\/p><\/dd>\n<dt id=\"what%20web%20server%20does%20this%20plugin%20support%3F\"><h3>What web server does this plugin support?<\/h3><\/dt>\n<dd><p>Apache \u2014 Fully tested and supported. <code>.htaccess<\/code> management features require Apache mod_rewrite.\nNGINX \u2014 Not officially tested. The <code>.htaccess<\/code> and robots.txt file management features may not behave as expected on NGINX servers, as NGINX does not use <code>.htaccess<\/code> files. Other features (SEO audit, meta tags, backup) should still function normally.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20slow%20down%20my%20site%3F\"><h3>Does the plugin slow down my site?<\/h3><\/dt>\n<dd><p>No. All audit operations run on demand from the admin area. The only frontend output is the meta tags injected into <code>&lt;head&gt;<\/code> (if NX Meta Generator is enabled for a page), which is negligible.<\/p><\/dd>\n<dt id=\"will%20my%20data%20be%20deleted%20when%20i%20deactivate%20the%20plugin%3F\"><h3>Will my data be deleted when I deactivate the plugin?<\/h3><\/dt>\n<dd><p>By default, no. You can enable the option <strong>Delete plugin database tables on deactivation<\/strong> from Settings if you want a clean uninstall.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>The plugin includes a dedicated eCommerce auditor (<code>class-ecommerce-auditor.php<\/code>) and can audit WooCommerce product pages when the <code>product<\/code> post type is added to the audit scope in Settings.<\/p><\/dd>\n<dt id=\"what%20php%20version%20is%20required%3F\"><h3>What PHP version is required?<\/h3><\/dt>\n<dd><p>PHP 7.4.3 or higher. PHP 8.3+ is recommended for best performance.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20free%3F\"><h3>Is the plugin free?<\/h3><\/dt>\n<dd><p>Yes. Free for personal use without limits. Not licensed for commercial resale or redistribution.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>5.3.0<\/h4>\n\n<ul>\n<li>COMPLIANCE \u2014 Removed the free-form \"paste your own code\" input from the CSS\/JS Minify &amp; Unminify tool. It now only works on real, already-published CSS\/JS files fetched from the site itself (via \"Send to Minifier\"), never on arbitrary typed\/pasted code. The duplicate minifier previously also present in DB Optimizer has been removed; there is now a single tool, in Minify Analyzer.<\/li>\n<li>SECURITY \u2014 Inline JSON passed to the Dashboard's charts (<code>wpsapPagesData<\/code>, <code>wpsapIssuesData<\/code>) is no longer emitted with unescaped forward slashes, preventing a <code>&lt;\/script&gt;<\/code> sequence in page titles\/URLs\/issue text from being able to break out of the inline script block.<\/li>\n<li>CODE QUALITY \u2014 Added a defensive shutdown-time safety net that flushes any output buffer the plugin may have left open, on top of auditing every ob_start()\/ob_get_clean() pair in the codebase to confirm none of them can be interrupted by another component mid-buffer.<\/li>\n<li>Renamed an unprefixed transient key in the upsell cache to use the plugin's own prefix.<\/li>\n<\/ul>\n\n<h4>5.2.0<\/h4>\n\n<ul>\n<li>SECURITY\/COMPLIANCE \u2014 Removed the wp-config.php raw code editor entirely. The plugin no longer offers any screen that saves free-form PHP into wp-config.php, .htaccess, or robots.txt. This also removed the associated backup\/restore-by-timestamp feature for that editor, which is no longer needed.<\/li>\n<li>COMPLIANCE \u2014 The plugin no longer writes to any file at the WordPress site root. The \"Preventive Settings\" tool in DB Optimizer (post revisions, autosave interval) now generates a ready-to-paste code snippet instead of editing wp-config.php directly. The Table Prefix Rename tool renames the database tables (unchanged) but no longer patches wp-config.php automatically; it now shows the exact $table_prefix line to paste in manually.<\/li>\n<li>COMPLIANCE \u2014 robots.txt is now managed virtually through WordPress core's own <code>robots_txt<\/code> filter when no physical robots.txt file exists at the site root, instead of writing a physical file. If a physical robots.txt already exists (owned by the site or another plugin), this plugin only offers to manage its file permissions and does not touch its content.<\/li>\n<li>COMPLIANCE \u2014 .htaccess changes (Force HTTPS redirect, initial file creation) now go through WordPress core's own <code>insert_with_markers()<\/code> and <code>save_mod_rewrite_rules()<\/code> functions instead of manual file read\/write.<\/li>\n<li>SECURITY \u2014 Completed a full sanitization pass across all AJAX and form-submission handlers: every <code>$_POST<\/code>\/<code>$_GET<\/code> value is now explicitly wrapped with <code>wp_unslash()<\/code> before the appropriate sanitization function (<code>sanitize_text_field()<\/code>, <code>sanitize_email()<\/code>, <code>sanitize_key()<\/code>, <code>absint()<\/code>, etc.), including IP-detection headers used internally for rate limiting.<\/li>\n<li>CODE QUALITY \u2014 Removed now-unused database-stored file-backup helper functions left over after the wp-config.php editor removal.<\/li>\n<\/ul>\n\n<h4>5.1.8<\/h4>\n\n<ul>\n<li><p>SECURITY \u2014 SMTP password now encrypted at rest.\nThe SMTP password configured in Settings was previously stored in plain text in the WordPress database via update_option(). It is now encrypted using openssl_encrypt() with AES-128-CBC and WordPress-unique keys (wp_salt + AUTH_KEY) before being saved. The password is decrypted transparently when the mailer uses it. Falls back safely if OpenSSL is unavailable on the server.<\/p><\/li>\n<li><p>SECURITY \u2014 SSRF protection added to Minify Analyzer endpoints.\nThe AJAX endpoints that fetch CSS\/JS assets accepted a URL from $_POST without validating the resolved IP address, which could allow requests to private or loopback network ranges. A new is_private_ip() helper now blocks requests to 127.0.0.1, 192.168.x.x, 10.x.x.x, 172.16.x.x and all reserved ranges using PHP's FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE before any HTTP request is made.<\/p><\/li>\n<li><p>CODE QUALITY \u2014 Documented sslverify disabled across all audit classes.\nTen instances of 'sslverify' =&gt; false across class-ajax-handler.php, class-sitemap-generator.php, class-core.php, class-links-auditor.php, class-page-speed-auditor.php, and class-ecommerce-auditor.php now include inline comments explaining that SSL verification is intentionally disabled to support auditing of sites running on self-signed or locally-issued certificates in staging and local development environments.<\/p><\/li>\n<\/ul>\n\n<h4>5.1.7<\/h4>\n\n<ul>\n<li>BUG FIX \u2014 NX Meta Generator missing <code>&lt;title&gt;<\/code> tag on frontend: The SEO Title field was saved and visible in the NX Meta Generator preview, but the <code>&lt;title&gt;<\/code> tag was never injected into the actual page <code>&lt;head&gt;<\/code>. Added <code>pre_get_document_title<\/code> filter to override the WordPress default title, and added explicit <code>&lt;title&gt;<\/code> output inside <code>output_meta_tags()<\/code> when NX Meta Generator is enabled for a post\/page.<\/li>\n<\/ul>\n\n<h4>5.1.6<\/h4>\n\n<ul>\n<li>Stable release. Meta Tags Generator with full Open Graph, Twitter Card, Schema.org, and robots directive support.<\/li>\n<li>NX Meta Generator full-screen editor mode.<\/li>\n<li>Sitemap Generator with WP-Cron support.<\/li>\n<li>DB Optimizer with protected transient cleanup.<\/li>\n<li>Security Tools: XML-RPC disable, .htaccess, robots.txt, wp-config.php management.<\/li>\n<li>Backup &amp; Restore with protected uploads directory.<\/li>\n<li>Multilingual support: ES, DE, FR, IT, PT.<\/li>\n<li>Internal Link Graph visualisation.<\/li>\n<li>Keyword Cannibalization Detector.<\/li>\n<li>Duplicate Content Detector.<\/li>\n<li>Image Converter (WebP batch conversion).<\/li>\n<li>Email Notifications with custom SMTP.<\/li>\n<li>Rate Limiter and Admin Auth (NX Plugin Administrator).<\/li>\n<\/ul>","raw_excerpt":"Complete SEO &amp; Content Audit Tool \u2014 Meta Tags, Headings, Images, Links, Sitemap, Security, Backup &amp; Restore and much more.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/344577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=344577"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/netsolex"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=344577"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=344577"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=344577"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=344577"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=344577"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=344577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}