
Advanced Category and Custom Taxonomy Image Security & Risk Analysis
wordpress.org/plugins/advanced-category-and-custom-taxonomy-imageAdd Custom Image To Your Category / Custom Taxonomy Field With Advanced Category and Custom Taxonomy Image Plugin.
Is Advanced Category and Custom Taxonomy Image Safe to Use in 2026?
Generally Safe
Score 99/100Advanced Category and Custom Taxonomy Image has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "advanced-category-and-custom-taxonomy-image" plugin version 2.0.9 reveals a generally strong security posture with several good practices in place. Notably, the code exhibits 100% proper output escaping, 100% of SQL queries utilize prepared statements, and there are no detected file operations or external HTTP requests. The presence of a nonce check is also a positive indicator.
However, a critical concern arises from the complete lack of capability checks for any of the identified entry points, including the single shortcode. This means that any user, regardless of their role, could potentially trigger the functionality associated with this shortcode. The absence of taint analysis results, while potentially indicating no critical issues were found, could also mean that a comprehensive taint analysis was not performed or that the analysis tool had limitations in this specific case. The plugin has a history of one medium severity vulnerability related to Cross-site Scripting, which, though currently patched, suggests a past weakness in input sanitization or output encoding.
In conclusion, while the plugin demonstrates strong internal coding practices regarding SQL and output handling, the absence of robust authorization checks for its entry points presents a significant risk. The past XSS vulnerability, even if fixed, warrants continued vigilance, and the lack of comprehensive taint analysis leaves some uncertainty. Users should be aware of the potential for privilege escalation or unintended actions if an authenticated user with low privileges can exploit the shortcode's functionality.
Key Concerns
- No capability checks on entry points (shortcode)
- Past medium severity vulnerability (XSS)
Advanced Category and Custom Taxonomy Image Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Category and Custom Taxonomy Image <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via ad_tax_image Shortcode
Advanced Category and Custom Taxonomy Image Code Analysis
Output Escaping
Advanced Category and Custom Taxonomy Image Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Advanced Category and Custom Taxonomy Image Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Category and Custom Taxonomy Image Alternatives
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Custom Category Image
custom-category-image
Are you looking for uploading image to a category ? Yes, Custom Category Image plugin exactly does that.
RDV Category Image
rdv-category-image
Add an image to a category or taxonomy. Display a category image using either a template tag or a shortcode.
TCL Categories Image
tcl-categories-image
TCL Categories Images Plugin allow users to add an image to category or custom taxonomies.You can easily assign an image to each category/taxonomy or …
Category Image Manager by DevDesignDazzle
category-image-manager-by-devdesigndazzle
Category Image Manager by DevDesignDazzle is a lightweight WordPress plugin to add images to WordPress categories.
Advanced Category and Custom Taxonomy Image Developer Profile
32 plugins · 10K total installs
How We Detect Advanced Category and Custom Taxonomy Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-category-and-custom-taxonomy-image/public/css/public.css/wp-content/plugins/advanced-category-and-custom-taxonomy-image/public/js/public.js/wp-content/plugins/advanced-category-and-custom-taxonomy-image/public/js/public.jsadvanced-category-and-custom-taxonomy-image/public/css/public.css?ver=advanced-category-and-custom-taxonomy-image/public/js/public.js?ver=HTML / DOM Fingerprints
taxonomy-imagedata-term-idACATTI_Admin/wp-json/advanced-category-and-custom-taxonomy-image/v1/settings