The Rank Math WordPress plugin has come under scrutiny due to security concerns involving the silent creation of administrator-level WordPress Application Passwords when users access the plugin’s Help & Support area. This raises critical questions about consent, authorization, and plugin security practices.
Understanding the Security Issue with Rank Math
WordPress Application Passwords are an official credential feature allowing third-party applications to interact securely with websites. These passwords are designed to be revocable, scoped per integration, and require explicit user approval before activation.
However, Rank Math reportedly bypassed these standard authorization protocols. When a user with administrator permissions opens the plugin’s Help & Support section, Rank Math automatically creates an Application Password tied to that user and sends it to the plugin developer’s servers without any prior notification or explicit user consent.
Security expert Sybere Waaijer stated: “When a site administrator whose site is connected to a (free) rankmath.com account opens ‘Help & Support,’ the plugin immediately creates a WordPress Application Password for that user. It sends that password to group.one’s servers. Their AI agent can then act on your behalf on your site.”
Lack of User Consent Violates WordPress Guidelines
WordPress plugin policies explicitly require plugins to obtain "explicit and authorized consent" from users before contacting external servers or generating credentials. This commonly involves opt-in mechanisms or clear authorization dialogs. Rank Math’s automatic password creation prior to presenting any terms or consent options contravenes these guidelines.
The official WordPress documentation clarifies that the Application Password flow must feature a user confirmation screen identifying the requesting application and allowing users to approve or reject password creation. In Rank Math’s case, this critical step is missing, effectively bypassing user authorization.
Implications for Website Security and Administration
Because the generated Application Password inherits the administrator-level permissions of the user, this grants the plugin developer extensive control over the site. This elevated access without explicit permission raises red flags about site security, trust, and accountability.
Users have noted that closing the Help & Support tab does not revoke the password, and the Application Password does not expire automatically. The only way to revoke it is manually through the WordPress user profile interface under Application Passwords.
Waaijer advised: “If you opened ‘Help & Support’ while connected, revoke the Application Passwords immediately. Go to ‘WP Admin -> Users -> Profile -> Application Passwords’ and revoke anything starting with ‘WAP –’.”
User Reactions and Community Response
The Rank Math plugin’s behavior has been met with strong user backlash on social media and community forums. Many have expressed outrage at the silent acquisition of admin privileges without consent, calling it a breach of trust and a dangerous practice.
User @tprinty tweeted: “This is horrible. WP needs SEO as part of core.”
Additionally, it was reported that the official Rank Math forum threads discussing this issue were removed, further fueling concerns about transparency and responsiveness to user complaints.
@CAwavehello commented: “There was a huge thread started on their WP forum page a few days ago and now it magically got deleted after all hell broke loose on their users forum. WTF?!”
Migration Away from Rank Math
Some users have decided to migrate their websites to alternative SEO plugins citing the security concerns as the primary motivator. The uncertainty around non-transparent access and potential vulnerabilities has undermined confidence in Rank Math.
@SwiftyLunatic shared: “Time to move my websites away from @rankmathseo. Why do this you shady company? Best SEO plugin to switch to, please?”
Rank Math’s Security History and Recommendations
Rank Math has had multiple reported vulnerabilities in recent years, including issues from unauthorized access to cross-site scripting exploits. Due to this security track record, it was not included in some trusted lists of recommended WordPress SEO plugins, emphasizing the importance of security in plugin evaluation.
Website administrators are urged to conduct thorough security checks on all installed plugins and monitor for unexpected access permissions or behaviors.
Revoking Rank Math’s Application Passwords for Improved Security
To mitigate the current risk, administrators can manually revoke the Application Passwords generated by Rank Math:
Navigate to Users > Your Profile > Application Passwords in the WordPress dashboard, identify any passwords labeled with "WAP – Rank Math Support Agent," and revoke them promptly to remove unauthorized access.
Balancing Automation and User Consent in WordPress Plugins
This controversy highlights the critical balance between automation convenience and respecting user consent and security in plugin design. Plugins providing advanced functionalities like AI-powered support must maintain transparency and explicit authorization in credential generation and data sharing.
For example, transparent consent flows combined with clear privacy policies and opt-in dialogs help build trust and comply with WordPress guidelines.
Further Reading on AI and Marketing Automation Security
For marketers interested in safe AI integration and advertising automation with guardrails, relevant insights can be found in articles about how to keep Meta campaigns within budget and control and the challenges of accountability when AI automates marketing.
How to Protect Your WordPress Site
Beyond revoking unauthorized Application Passwords, site administrators should regularly audit user roles and permissions, review installed plugins for security reputation, and monitor for unexpected network connections or data sharing.
Securing websites means verifying that plugins comply with WordPress’ explicit consent rules and privacy policies. Choosing trusted and transparent plugins is paramount for maintaining site integrity.
Solutions like Adsroid’s automation platforms offer controlled automation within defined guardrails, providing powerful marketing tools without compromising security or consent principles.
Conclusion
The recent Rank Math security issue exemplifies how plugin shortcuts in authorization processes can jeopardize website security and user trust. Users must remain vigilant, demand transparency, and proactively manage plugin credentials and permissions.
When choosing SEO or automation plugins, prioritize those adhering strictly to WordPress security guidelines and with a proven record of responsible data handling and user consent.
To explore secure automation for marketing campaigns with AI agents that respect guardrails and ethical standards, learn more at Adsroid’s AI agent solutions.