Fresh allegations have emerged regarding the Rank Math WordPress plugin, suggesting it has silently incorporated a feature that grants administrator-level access to company personnel across WordPress sites.
This unwarranted access is reportedly activated when a user connects to a complimentary Rank Math account and subsequently navigates to the plugin’s Help & Support section.
Allegations of Absence of Consent and Notification
Recently, the developer of The SEO Framework plugin raised concerns via Twitter about how accessing Rank Math’s Help & Support section instigates the creation of a WordPress Application Password linked to the user accessing that section.
If the user possesses administrator-level permissions, the newly generated Application Password from Rank Math inherits these elevated rights.
Sybre Waaijer elucidated:
“Just two days prior, Rank Math addressed approximately a dozen security vulnerabilities in version 1.0.277. This plugin is employed on over 4 million sites.
In this update, group[.]one (which also owns WP Rocket) has now acquired administrative access to your website.
Previously, I characterized a similar issue as a backdoor. This time, the decision is yours.
The file in question: vendor/groupone/wap-client/includes/class-app-password-manager.php.
Functionality:
When a site administrator connected to a free rankmath[.]com account accesses “Help & Support,” the plugin instantaneously generates a WordPress Application Password for that user and transmits it to group[.]one’s servers. Their AI can then operate on your behalf on your site.”
Understanding WordPress Application Passwords
WordPress Application Passwords are an established feature within the WordPress ecosystem, integral to its core functionality, allowing plugins to function effectively.
Guidelines exist to instruct developers on the proper methodology for generating these passwords, which likely explains why Waaijer hesitated to outright label Rank Math’s behavior as backdoor activity.
Rank Math’s Lack of Authorization Request
A principal objection raised by Waaijer centers around Rank Math’s approach to generating these permission levels.
He stated:
“The plugin never prompts for consent. Although there is a ‘Terms & Conditions’ checkbox, it does not halt the password creation or transmission. The data transfer initiates before the checkbox even becomes visible.”
User Authorization Integral to WordPress’s Application Password Framework
The official WordPress documentation delineates an authorization interface that identifies the plugin, presenting the connection to the user with an opportunity to approve or decline.
The essence of the specification is that the Application Password is only relayed to the plugin after receiving user approval.
Illustration of Authorization Protocol
Explicit Consent Mandate by WordPress.org
WordPress’s plugin development regulations stipulate a mandatory explicit consent requirement concerning external server communications.
According to the guidelines, plugins are forbidden from contacting external servers absent “explicit and authorized consent,” typically necessitating an opt-in checkbox. Moreover, automated data collection from users without their explicit agreement is prohibited.
The guidelines specify:
7. Plugins may not track users without their consent.
To safeguard user privacy, plugins are prohibited from contacting external servers without explicit and authorized consent.
This is typically conducted through an ‘opt-in’ mechanism, requiring service registration or a checkbox within plugin settings.
Documentation outlining any user data collection and usage should be included in the plugin’s readme, ideally with a clear privacy policy.
Revocable Nature of Application Passwords
According to WordPress guidelines, Application Passwords are intended to be individual, revocable credentials.
“Application Passwords are a feature in WordPress that enables you to create revocable credentials for each application…”
Moreover, it is noted:
“An Application Password is:
Individually revocable, allowing the disabling of a single integration without altering the user’s primary password.”
Waaijer offered instructions on how to revoke the Application Password triggered by the Rank Math support agent:
“The password is listed on your profile as ‘WAP – Rank Math Support Agent’. Simply closing the ‘Help & Support’ tab does not revoke it. This Application Password remains active indefinitely. You are unable to disable the ‘Support Agent’ functionality.
To revoke the Application Passwords:
Navigate to ‘WP Admin -> Users -> Profile -> Application Passwords, and revoke anything designated as ‘WAP –’.”
User Sentiments
The response from users has been overwhelmingly negative.
@tprinty’s tweet encapsulated the widespread discontent directed toward Rank Math:
“This is appalling. WordPress requires SEO to be part of the core functionalities.”
Accusations of Complaints Being Erased
@CAwavehello asserted that an extensive thread on the Rank Math forum discussing this matter was subsequently deleted, presumably by Rank Math itself.
@CAwavehello commented:
“I was perplexed by the uproar. A significant thread was initiated on their WP forum days ago, and now it has mysteriously disappeared. I received a notification today that they had erased it after the situation escalated in their user forum. What is going on?!”
Migration from Rank Math
@SwiftyLunatic expressed intentions to transition their websites away from Rank Math:
“I am compelled to relocate my websites away from @rankmathseo.
Why adopt such practices, you dubious organization? Please recommend a more trustworthy SEO plugin!”
@SEOMastery2026 tweeted:
“So, admin access is granted without consent?”
Rank Math Excluded from SEJ’s Trusted Plugin Compilation
Rank Math has not secured a spot on Search Engine Journal’s roster of recommended WordPress plugins, as one of the critical criteria is trustworthiness, which includes a clean record devoid of vulnerabilities.

Rank Math has reported seven vulnerabilities in 2024, four in 2025, and three to date in 2026, including a recent vulnerability concerning Unauthenticated Stored Cross-Site Scripting. A meticulous evaluation of all utilized plugins, including comprehensive security checks, is advised.
Source link: Searchenginejournal.com.




