
WP Calais Auto Tagger Security & Risk Analysis
wordpress.org/plugins/calais-auto-taggerThe plugin performs semantic analysis of your posts to suggest tags using Open Calais.
Is WP Calais Auto Tagger Safe to Use in 2026?
Use With Caution
Score 63/100WP Calais Auto Tagger has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The calais-auto-tagger plugin v2.0 presents a significant security risk due to several critical vulnerabilities identified in the static analysis. The presence of an unprotected AJAX handler is a major concern, as it represents a direct entry point into the plugin's functionality without any authentication or authorization checks. This could be exploited by attackers to perform unauthorized actions. Compounding this, the code analysis indicates a complete lack of output escaping, meaning any data processed or displayed by the plugin could be vulnerable to cross-site scripting (XSS) attacks. While the plugin shows good practices in using prepared statements for SQL queries and avoids file operations, these strengths are overshadowed by the critical weaknesses in its attack surface and output handling. The vulnerability history, including a known unpatched medium-severity CVE related to CSRF, further highlights a pattern of security negligence. This suggests that the plugin has a history of introducing exploitable flaws, and the current version has not addressed all past issues. Overall, the plugin's security posture is poor, with immediate action required to mitigate the identified risks.
Key Concerns
- Unprotected AJAX handler
- No output escaping
- Missing nonce checks on AJAX
- Missing capability checks
- Unpatched CVE (medium severity)
WP Calais Auto Tagger Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Calais Auto Tagger <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WP Calais Auto Tagger Code Analysis
Output Escaping
Data Flow Analysis
WP Calais Auto Tagger Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
WP Calais Auto Tagger Maintenance & Trust
Maintenance Signals
Community Trust
WP Calais Auto Tagger Alternatives
YQL Auto Tagger
yql-auto-tagger
The plugin performs an analysis of your post text and suggests tags for you.
WP Calais Archive Tagger
wp-calais-archive-tagger
Goes through your archives and adds tags to your posts based on semantic analysis.
Already Existing Tags
already-existing-tags
Looks for already existing tags within your posts.
Climate Tagger
climate-tagger
Suggests tags for your posts based on an experts-vetted climate thesaurus, using the Climate Tagger API
tags.mowster
mowster-tags
Tags suggestions using YQL Yahoo Content Analysis API.
WP Calais Auto Tagger Developer Profile
3 plugins · 70 total installs
How We Detect WP Calais Auto Tagger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calais-auto-tagger/calais.css/wp-content/plugins/calais-auto-tagger/calais.js/wp-content/plugins/calais-auto-tagger/calais.jsHTML / DOM Fingerprints
id="calais_taglist"calais_gettags/wp-json/calais_gettags