Rank Math Accused of a Silent Backdoor: What 4 Million WordPress Site Owners Should Do Now
Hi everyone, this is Neo.
I need to interrupt the regular schedule with an urgent security alert — this one concerns anyone running an independent site on WordPress.
In the last couple of days, Rank Math, one of the biggest SEO plugins in the WordPress ecosystem (the company says it runs on 4+ million websites), has been accused of a very serious problem: when you’re logged into a free Rank Math account and open the plugin’s “Help & Support” section, the plugin silently creates a WordPress Application Password at your current permission level and sends it to the servers of its parent company, group.one.
If you opened that page as an administrator, the key it generates is admin-level. Theoretically, group.one’s AI agent could then act on your site as you.
This isn’t fear-mongering — it’s a technical accusation laid out publicly by a plugin developer. Let me walk you through exactly what happened, then give you a 10-minute checklist.
What happened, in one paragraph
On August 28, Sybre Waaijer, the developer of the competing SEO plugin The SEO Framework, posted a thread on X. His words, roughly:
“Two days ago, Rank Math closed about a dozen security issues in 1.0.277. This plugin runs on over 4 million sites.
In that same update, group[.]one (who also owns WP Rocket) now gets administrative privileges to your site.
Last time, I classified something like this as a backdoor. This time, you may decide.“
He pointed to a specific code file — vendor/groupone/wap-client/includes/class-app-password-manager.php — and described the trigger mechanism:
When your site is connected to a (free) rankmath.com account and an administrator opens the plugin’s Help & Support section, the plugin immediately creates a WordPress Application Password for that user and sends it to group.one’s servers. Their AI agent can then act on your behalf on your site.
The thread blew up across the SEO community within hours, Search Engine Journal and other outlets covered it, and plugin forums lit up.
How the “spare key” actually works
Let me translate the technical terms first.
WordPress Application Passwords are a legitimate core feature introduced in WordPress 5.6 (December 2020): you can generate a separate credential for a third-party app (a mobile app, a script, an API tool), revoke it individually at any time, and never expose your main account password. WordPress’s own docs describe them as “revocable, per-application credentials.” It’s a security feature done right — you shouldn’t have to hand your admin password to any third party.
The problem is how Rank Math created and used this one:
- No user consent. Simply opening the Help & Support page triggered the creation. Waaijer’s words: “The plugin never asks first. There is a ‘Terms & Conditions’ box, but it does not stop the password from being created or sent — the transfer starts before the box even appears.”
- Permission inheritance. Whoever opened the page got a password at their own level. An admin clicking around = an admin-level key.
- It shows up in your profile named “WAP – Rank Math Support Agent.”
- It never expires and can’t be turned off. Closing the Help & Support tab doesn’t revoke it, and there’s no “disable support agent” switch. The only way to kill it is to delete it manually from your profile.
In plain English: you clicked “contact support,” and your site handed a spare admin-level key to a third party’s servers — a key that never expires and can’t be recalled automatically.
Why this is serious: checked against the official rules
Someone might argue: Application Passwords are an official WordPress feature, so using them can’t be a violation, right?
Using Application Passwords is fine. Silently creating one and shipping it off-site is not. Measured against WordPress’s own rules, this one trips nearly every line:
1. The official integration guide requires an authorization flow
WordPress’s Application Passwords integration guide spells out the flow: the plugin must first show an authorization screen identifying itself, and the password is only passed to the plugin after the user approves or rejects the connection. Rank Math did the opposite — the password was created and transmitted before the user ever saw an option.
2. Plugin guideline #7 prohibits unauthorized external communication
WordPress’s plugin guidelines, rule 7: “Plugins may not track users without their consent. In the interest of protecting user privacy, plugins may not contact external servers without explicit and authorized consent. This is commonly done via an ‘opt in’ method, requiring registration with a service or a checkbox within the plugin settings.”
Rank Math’s checkbox doesn’t qualify as “explicit and authorized consent” — whether it exists or is ticked has zero effect on whether the password gets created and sent.
3. The permission scope is wildly excessive
Even if an “AI support agent” is a legitimate product idea, the normal way to build it is: minimum necessary permissions, explicit disclosure, and a revocable grant. Silently creating a credential at the current user’s level — admin privileges for admins — is far beyond what “customer support” needs.
An analogy: apartment buildings use a standardized lock system (Application Passwords themselves are fine). Then one day the property company secretly copies your master key card and sends it to their head office, saying “this is for easier maintenance visits.” The card never expires and can’t be deactivated. Is that convenience reasonable?
Who’s making the accusation — and does it hold up?
Let me be fair here: Waaijer is a direct competitor (The SEO Framework competes with Rank Math), and his tone carries competitive friction. Fair enough.
But note: this accusation is not speculation — it’s based on direct code analysis. He named a specific file path and a specific trigger sequence, and the outlets covering it verified the details.
In other words: you can question his motives, but code doesn’t lie. Whether this mechanism exists is verifiable by looking at the file and the behavior.
One more piece of context from the coverage: Search Engine Journal has never put Rank Math on its “recommended plugins” list, because their bar for recommendation includes “no history of vulnerabilities.” Rank Math’s public vulnerability record: 7 in 2024, 4 in 2025, and 3 so far in 2026 — including a recent unauthenticated stored XSS. That track record is part of why the reaction has been so fierce.
The community response: anger, deleted threads, and people leaving
The reaction across X and the WordPress forums was overwhelmingly negative:
- One user put it bluntly: “This is horrible. WP needs SEO as part of core.”
- Another claimed Rank Math’s own forum had a big thread on the topic — which then “magically” got deleted: “There was a huge thread started on their WP forum page a few days ago and now it magically got deleted. Got the notification today they deleted it after all hell broke loose on their users forum.”
- And some were already packing: “Time to move my websites away from Rank Math. Why do this, you shady company. Best SEO plugin to switch to, please?”
As of this writing, Rank Math has not issued a public statement — I checked their site and blog before publishing this. Hopefully they’ll respond responsibly: either explain the intended design and authorization logic, or acknowledge the problem and commit to fixing it.
Your 10-minute checklist, right now
Whether you use Rank Math or are considering it, run through these steps:
Step 1: Check for a rogue Application Password
Log into wp-admin, go to Users → Profile, scroll down to the Application Passwords section, and look for anything starting with “WAP –” (the full name looks like “WAP – Rank Math Support Agent”).
If it’s there: click “Revoke” immediately. This is the known, direct cleanup. Closing the Help & Support tab does NOT revoke it — you have to delete it manually.
Step 2: Disconnect your rankmath.com account
If you registered and connected a free Rank Math account to use its features, disconnect it in the plugin settings. The account connection is the trigger’s first half — no connection, no password generation path. If you can’t figure out how, skip to step 4 — disabling is the blunt fix.
Step 3: Update the plugin — and everything else
Version 1.0.277 fixed roughly a dozen security issues, and a follow-up fix for this incident should be coming. Keep auto-updates on and manually check for a new version once. While you’re at it, check every other plugin on the site — plugins that haven’t been updated in a long time are ticking time bombs.
Step 4 (high-risk sites): disable it until there’s an answer
If this is a business-critical site, or you just don’t want the uncertainty: deactivate Rank Math in your plugin list and wait for an official response before deciding whether to re-enable. A few days without your SEO plugin will not tank your rankings. A suspicious admin-level spare key on your server just might.
Step 5: Hardening while you’re in there
- Audit all user roles and remove unused admin accounts (least-privilege principle);
- Enable two-step authentication — admins first;
- Confirm your backup routine actually works — files AND database, and test the restore process at least once.
Neo’s take
A few final thoughts.
First, this is a story about the business model of “free” tools. How does a free SEO plugin like Rank Math make money? Through upsells, premium tiers, and — let’s be honest — data. Lots of tools have been pushing “AI support agents” lately, and from a business standpoint I get it: free users are too many to support with humans, and AI cuts costs. Understanding isn’t accepting, though. AI-powered support is fine; the problem is the permission boundary and consent. You can access the data the user authorized you to use — you can’t silently take an admin-level key. That crosses the trust line.
Second, free is often the most expensive thing you’ll ever buy. This is especially true in the plugin ecosystem. The few hundred dollars a year you save with a free plugin can cost you control over your site’s data — or its admin panel. My advice has always been boring and reliable: for core-site-critical plugins, prefer ones with a healthy business model (paid tiers are a plus), open and auditable code, active updates, and a clean security record. The smart way to save money is picking the right free tools, not installing a pile of them.
Third, this line is going to get blurrier — because AI agents are coming to your site either way. A few days ago, ChatGPT officially announced WebMCP support — AI agents performing actions inside websites is becoming a platform standard. Once “an AI agent does things for you on your site” is normal, “what exactly can a third party touch on my site” stops being a security niche and becomes a daily operational question for every site owner. This Rank Math incident is essentially a preview of the AI-agent permission problem: a vendor wanted to send an AI into your site without being clear about what permissions it needed or why. From now on, any “connect account / authorize / generate credential” flow deserves a second look.
Fourth — don’t uninstall in a panic, but take it seriously. Right now this is an accusation with public technical details and no official response yet. I wouldn’t let emotion drive you to migrate immediately — moving SEO plugins costs real time (redirects, schema, meta setups). The right move: check, revoke, disconnect, close the exposure — then wait for the vendor’s answer. If they can’t give a convincing explanation, migration is always on the table later.
I’ve said it before and I’ll say it again: website security is never a question of whether something will happen — it’s a question of when. Ten minutes of checking now can save you from a disaster later.
Go check your dashboard. Questions welcome in the comments.