
Category- and Tag-Feeds Security & Risk Analysis
wordpress.org/plugins/category-and-tag-feedsGet full control over the output of WordPress-generated feeds of your categories and keywords!
Is Category- and Tag-Feeds Safe to Use in 2026?
Generally Safe
Score 100/100Category- and Tag-Feeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-and-tag-feeds" plugin version 1.1.7 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by avoiding dangerous functions and file operations. Significantly, all SQL queries are executed using prepared statements, and the vast majority of outputs are properly escaped, reducing the risk of common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The total attack surface is small, and importantly, all identified entry points (AJAX, REST API, shortcodes) appear to be protected by authentication or permission checks, which is a critical security measure. The absence of any known CVEs, past or present, further reinforces its current security standing. There are no recorded taint flows, indicating no identified vulnerabilities related to unsanitized data processing.
Despite the positive findings, there are minor areas for attention. The lack of nonce checks, while not directly flagged as a vulnerability due to other protections, can sometimes be an indicator of incomplete security hardening, especially if the protections are solely reliant on other mechanisms. While the capability check is present, it's a single instance, and a more comprehensive security review might explore if all functions are adequately protected. However, given the overall clean analysis and vulnerability history, the immediate risks are very low. The plugin's strengths in secure SQL handling and output escaping, coupled with a protected attack surface, make it a relatively safe option.
Key Concerns
- No nonce checks
- Limited capability checks (1)
Category- and Tag-Feeds Security Vulnerabilities
Category- and Tag-Feeds Code Analysis
Output Escaping
Category- and Tag-Feeds Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 25
Maintenance & Trust
Category- and Tag-Feeds Maintenance & Trust
Maintenance Signals
Community Trust
Category- and Tag-Feeds Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Pages with category and tag
pages-with-category-and-tag
Add Categories and Tags to Pages.
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Category- and Tag-Feeds Developer Profile
4 plugins · 310 total installs
How We Detect Category- and Tag-Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-and-tag-feeds/css/style.csscategory-and-tag-feeds/css/style.css?ver=HTML / DOM Fingerprints
lw-cf-rss-listlw_cf_get_rss_types/wp-json/lwcf/v1/rssTypes/<ul class="lw-cf-rss-list"><li><a href="