
Configurable Tag Cloud (CTC) Security & Risk Analysis
wordpress.org/plugins/configurable-tag-cloud-widgetDisplay a tag cloud customized with your preferences in the sidebar.
Is Configurable Tag Cloud (CTC) Safe to Use in 2026?
Generally Safe
Score 85/100Configurable Tag Cloud (CTC) has a strong security track record. Known vulnerabilities have been patched promptly.
The "configurable-tag-cloud-widget" plugin v5.3 presents a generally good security posture based on the static analysis. The complete absence of SQL queries without prepared statements, file operations, and external HTTP requests is a strong indicator of secure coding practices. Furthermore, the limited attack surface with zero unprotected entry points (AJAX, REST API, shortcodes, cron) is commendable. However, a significant concern arises from the output escaping, where only 56% of outputs are properly escaped. This leaves a substantial portion of dynamic content potentially vulnerable to Cross-Site Scripting (XSS) attacks if not handled carefully by the WordPress core or themes. The plugin's vulnerability history, while currently clear of unpatched issues, shows a past medium severity vulnerability and a common trend of Cross-Site Request Forgery (CSRF). This suggests a need for ongoing vigilance and robust input validation and output escaping, especially since CSRF is often linked to actions that might involve user interaction and thus require nonce protection.
Key Concerns
- Output escaping is below 75%
- History of medium severity vulnerability
- History of CSRF vulnerabilities
Configurable Tag Cloud (CTC) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Configurable Tag Cloud <= 5.2 - Cross-Site Request Forgery via ctc_options_page()
Configurable Tag Cloud (CTC) Code Analysis
Output Escaping
Data Flow Analysis
Configurable Tag Cloud (CTC) Attack Surface
WordPress Hooks 3
Maintenance & Trust
Configurable Tag Cloud (CTC) Maintenance & Trust
Maintenance Signals
Community Trust
Configurable Tag Cloud (CTC) Alternatives
Ultimate Tag Cloud Widget
ultimate-tag-cloud-widget
This plugin aims to be the most configurable tag cloud widget out there, able to suit all your weird tag cloud needs.
Random Tags Cloud Widget
random-tags-cloud-widget
Random Tags Cloud displays your tags by selecting randomly. Of course, you can customize other tag cloud's settings.
Muki Tag Cloud
muki-tag-cloud
Another wordpress tag cloud plugin based on jQCloud, which is creative, beauty and colorful.
Tag Cloud Widget
tag-cloud-widget
A tag cloud widget with links to your tag pages
Tags Page
tags-page
Adds a table listing all tags registered on your website.
Configurable Tag Cloud (CTC) Developer Profile
1 plugin · 2K total installs
How We Detect Configurable Tag Cloud (CTC)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/configurable-tag-cloud-widget/widget_28.css/wp-content/plugins/configurable-tag-cloud-widget/style.css/wp-content/plugins/configurable-tag-cloud-widget/admin_page.js/wp-content/plugins/configurable-tag-cloud-widget/admin_page.jsconfigurable-tag-cloud-widget/widget_28.css?ver=configurable-tag-cloud-widget/style.css?ver=configurable-tag-cloud-widget/admin_page.js?ver=HTML / DOM Fingerprints
ctc_tag_cloud<!-- Configurable Tag Cloud Widget -->data-ctc-max-font-sizedata-ctc-min-font-sizedata-ctc-number-of-tagsdata-ctc-order-bydata-ctc-unit[tag_cloud]