Rank Math, an SEO plugin running on more than four million WordPress installs, silently creates an administrator-level credential the moment certain users open one settings tab, according to allegations from a competing developer. Sybre Waaijer, who builds the rival plugin The SEO Framework, made the claim after inspecting code shipped in version 1.0.277. The stakes are immediate for anyone managing client sites: a credential issue at this install base reaches agencies and freelancers who have never looked at this part of the codebase.
Waaijer says the trigger is narrow but consequential. A site owner who has linked a no-cost Rank Math account and then clicks into Help & Support, he wrote, causes the plugin to mint a WordPress Application Password, a native WordPress credential type meant to be revocable and scoped. Because that password takes on whatever permission level the clicking user holds, an administrator opening that tab hands out full site control, Waaijer says, to servers operated by group.one, Rank Math’s owner, which also runs WP Rocket.
His sharper objection is about timing, not the credential mechanism itself. Waaijer described a “Terms & Conditions” prompt that appears in the interface but, in his account, does nothing to pause password creation or transmission, which he says both begin before that prompt even renders. WordPress’s own integration guide for this credential type calls for a confirmation screen naming the requesting plugin, letting the user review the request and either approve or decline it first.
That sequence, if accurate, would sit awkwardly beside WordPress.org’s developer rules for outside connections. Those rules bar a plugin from reaching an external server unless the person running the site has given informed, opted-in permission, commonly through a checkbox, and they separately forbid gathering user data automatically without that same confirmation. Rank Math has not issued a public statement answering Waaijer’s specific description of the flow; its changelog for 1.0.277 describes the release as a security update rather than a new way of sharing account data, a characterization Waaijer contests.
Reaction on X ran entirely negative. One user, @CAwavehello, said a lengthy forum thread on Rank Math’s own site describing the behavior disappeared not long after drawing attention, though the outlet reporting this could not confirm who removed it. Other users, among them @SwiftyLunatic, said they were dropping the plugin outright.
Waaijer’s advice for anyone who may be affected: check the WordPress profile’s Application Passwords list for any entry labeled “WAP” and revoke it, since he says the credential never expires on its own and simply closing the support panel leaves it active.
The allegation lands on a plugin that Search Engine Journal had already excluded from its own roundup of vetted WordPress tools, a list built partly around a clean security record. Rank Math disclosed seven vulnerabilities in 2024, four in 2025, and three so far this year, most recently an unauthenticated stored cross-site scripting flaw.
Agencies running client sites on Rank Math should not treat this as something to monitor passively. Any site tied to a connected free account merits an immediate check of its Application Passwords list, whether or not staff remember opening the support panel, and this incident belongs in vendor risk reviews before the next plugin update lands.
Search Engine Journal’s Roger Montti reported these allegations on August 30, 2026, based on Sybre Waaijer’s public statements.