
Doc’s Auto-tags Security & Risk Analysis
wordpress.org/plugins/docs-auto-tagsAssigns tags and/or categories to posts containing specific text strings, handy for filtering within the loop.
Is Doc’s Auto-tags Safe to Use in 2026?
Generally Safe
Score 85/100Doc’s Auto-tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "docs-auto-tags" v0.7.1 exhibits a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities (CVEs) and demonstrates good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and conducting file operations securely. The attack surface is commendably zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation.
However, a significant concern arises from the output escaping. With 27 total outputs and only 4% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Although taint analysis did not reveal any critical or high-severity issues, the lack of proper output sanitization for the majority of outputs is a critical weakness that could be leveraged by attackers to inject malicious scripts. The presence of capability checks is a positive sign, but its effectiveness is undermined by the widespread output escaping issues.
In conclusion, while the plugin is clean in terms of known vulnerabilities and attack surface, the severe deficiency in output escaping presents a substantial risk. This is the primary area requiring immediate attention to prevent potential XSS attacks. The plugin's history of no vulnerabilities is positive, but the current code analysis reveals a significant blind spot that needs to be addressed to maintain its secure reputation.
Key Concerns
- Low percentage of properly escaped output
Doc’s Auto-tags Security Vulnerabilities
Doc’s Auto-tags Code Analysis
Output Escaping
Doc’s Auto-tags Attack Surface
WordPress Hooks 5
Maintenance & Trust
Doc’s Auto-tags Maintenance & Trust
Maintenance Signals
Community Trust
Doc’s Auto-tags Alternatives
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Enhanced Media Library
enhanced-media-library
This plugin would be handy for those who need to manage a lot of media files.
Media Library Assistant
media-library-assistant
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
Doc’s Auto-tags Developer Profile
1 plugin · 100 total installs
How We Detect Doc’s Auto-tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/docs-auto-tags/docs-auto-tags.phpHTML / DOM Fingerprints
suggest-tagsuggest-categorydata-multipledata-multiple-sep/wp-json/wp/v2/tags/wp-json/wp/v2/categories