
Commenters can add tags Security & Risk Analysis
wordpress.org/plugins/commenters-can-add-tagsCommenters can add tags allows commenters to add tags to a post just by adding a prefixed word in a comment. Prefix is # by default.
Is Commenters can add tags Safe to Use in 2026?
Generally Safe
Score 85/100Commenters can add tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'commenters-can-add-tags' plugin, version 0.2, presents a generally strong security posture with no reported vulnerabilities and a limited attack surface. The static analysis indicates no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. Furthermore, all SQL queries are confirmed to be using prepared statements, a critical practice for preventing SQL injection. The absence of dangerous functions and file operations also contributes to a positive security outlook.
However, a significant concern arises from the output escaping analysis. With 0% of the identified outputs properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users without proper sanitization could be exploited by attackers to inject malicious scripts. The presence of a single capability check without any nonce checks for the identified flows is also a weakness, though the overall lack of entry points mitigates this risk to some extent. The plugin's history of zero known CVEs is a strong positive indicator, suggesting consistent security development or a low profile that has not attracted widespread vulnerability discovery.
In conclusion, while the plugin benefits from a minimal attack surface and secure database practices, the lack of output escaping is a critical flaw that needs immediate attention. This oversight could lead to severe security issues, outweighing the benefits of its otherwise robust design. Addressing the XSS risk is paramount to improving its overall security. The vulnerability history is reassuring but does not negate the immediate risks identified in the code analysis.
Key Concerns
- Unescaped output identified
- Missing nonce checks on identified flows
Commenters can add tags Security Vulnerabilities
Commenters can add tags Code Analysis
Output Escaping
Data Flow Analysis
Commenters can add tags Attack Surface
WordPress Hooks 3
Maintenance & Trust
Commenters can add tags Maintenance & Trust
Maintenance Signals
Community Trust
Commenters can add tags Alternatives
XHTheme AI Toolbox
xhtheme-ai-toolbox
AI tag extraction, AI image, AI summary, comment generation, AI topic expansion, auto-classification, slug generation and AI content enhancement.
Simple Comment Quicktags
marctv-quicktags
Make commenting easier with bold, italic, add link and quote buttons on top of the form.
Comment Form Quicktags
comment-form-quicktags
This plugin inserts a quicktag toolbar on the comment form.
FF Tab Widget
ff-tab-widget
Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.
WP Russian Quicktags
wp-russian-quicktags
Плагин выводит панель с русскими кнопками форматирования текста в комментариях.
Commenters can add tags Developer Profile
3 plugins · 30 total installs
How We Detect Commenters can add tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.