
Automatic Tags Security & Risk Analysis
wordpress.org/plugins/automatic-tagsAutomatically tag and categorize your posts.
Is Automatic Tags Safe to Use in 2026?
Generally Safe
Score 85/100Automatic Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automatic-tags" plugin v0.1.0 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, not performing raw SQL queries, and not utilizing bundled libraries. The absence of any recorded vulnerabilities in its history is also a strong positive signal, suggesting the developers have been diligent about security or the plugin has not been extensively targeted. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without authentication checks, creating a substantial attack surface that could be leveraged by unauthenticated users. Additionally, while there are capability checks present, the lack of nonce checks on the unprotected AJAX handlers is a critical oversight, as it leaves these endpoints vulnerable to Cross-Site Request Forgery (CSRF) attacks. The incomplete output escaping (only 55% properly escaped) also suggests potential for Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is not handled carefully within the unescaped outputs.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Insufficient output escaping
Automatic Tags Security Vulnerabilities
Automatic Tags Code Analysis
Output Escaping
Data Flow Analysis
Automatic Tags Attack Surface
AJAX Handlers 2
REST API Routes 2
WordPress Hooks 10
Maintenance & Trust
Automatic Tags Maintenance & Trust
Maintenance Signals
Community Trust
Automatic Tags Alternatives
JSM Show Term Metadata
jsm-show-term-meta
Show term metadata in a metabox when editing terms - a great tool for debugging issues with term metadata.
Bulk Add Terms
bulk-add-terms
A lightweight plugin to add thousands of taxonomy terms in one go.
Term Taxonomy Converter
term-taxonomy-converter
Copy or convert terms between taxonomies.
E-Commerce Autocomplete Search Bar
woo-autocomplete-search-bar
E-Commerce Autocomplete Search Bar: An autocomplete searchbar for E-Commerce products, categories, tags, or taxonomy
Required Fields
required-fields
Required Fields can help you write your Posts, Pages without forgetting fields, if you forget something you'll be alerted about that!
Automatic Tags Developer Profile
1 plugin · 10 total installs
How We Detect Automatic Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-tags/style.css/wp-content/plugins/automatic-tags/js/wpat-cats.js/wp-content/plugins/automatic-tags/js/wpat-tags.jsautomatic-tags/style.css?ver=wpat-cats.js?ver=wpat-tags.js?ver=HTML / DOM Fingerprints
wpat_tag_containerwpat-suggest-action-headerwpat-suggest-action-linkdata-ajaxactionwpat_ajax_object_catswpat_ajax_object_tags