
Category Popular Tags Security & Risk Analysis
wordpress.org/plugins/category-popular-tagsDisplay popular tags on achieve/category page of your theme using sortcode or by calling a function.
Is Category Popular Tags Safe to Use in 2026?
Generally Safe
Score 100/100Category Popular Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-popular-tags" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Crucially, all detected SQL queries utilize prepared statements, and the limited attack surface (one shortcode) is not explicitly noted as unprotected. The lack of any known CVEs further reinforces its current safety profile.
However, there are areas for improvement. The plugin has a notable absence of nonce checks and capability checks. While the current static analysis did not identify any specific vulnerabilities stemming from this, it represents a potential weakness that could be exploited if the shortcode or other future entry points were to process user-supplied data in a sensitive manner. The output escaping, while mostly proper (80%), still leaves room for improvement, as 20% of outputs could potentially be vulnerable to cross-site scripting (XSS) if unsanitized data is ever passed through them.
In conclusion, "category-popular-tags" v1.0 is currently a low-risk plugin, demonstrating good practices in SQL handling and limiting its attack surface. Its clean vulnerability history is a significant positive. The primary concerns revolve around the missing security checks (nonces, capabilities) and the partially unescaped output, which are potential areas of future vulnerability, especially as the plugin evolves.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output (20% of 10)
Category Popular Tags Security Vulnerabilities
Category Popular Tags Code Analysis
SQL Query Safety
Output Escaping
Category Popular Tags Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Category Popular Tags Maintenance & Trust
Maintenance Signals
Community Trust
Category Popular Tags Alternatives
WP-Popular Posts Tool
wp-popular-posts-tool
Enables you to automatically display most commented posts, either by category or tag. Optional: You can choose manually the category or tag you want t …
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
Require Post Category
require-post-category
Require users to choose a post category before updating or publishing a post.
Most Popular Categories
most-popular-categories
Display your most popular categories in a widget
Simple Taxonomy Refreshed
simple-taxonomy-refreshed
This plugin provides a no-code facility to manage your taxonomies - either by defining your own or by adding additional function to existing ones.
Category Popular Tags Developer Profile
2 plugins · 2K total installs
How We Detect Category Popular Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-popular-tags/assets/plugin.cssplugin.css?ver=1.0HTML / DOM Fingerprints
window.cush_category_popular_tag_sc[popular_category_tags