
Dreamy Tags Security & Risk Analysis
wordpress.org/plugins/dreamy-tagsDreamy Tags displays a customizable tag cloud filtered by categories and tags for clean, meaningful blog and archive navigation.
Is Dreamy Tags Safe to Use in 2026?
Generally Safe
Score 100/100Dreamy Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dreamy-tags' plugin v1.0.76 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are excellent practices that significantly reduce the risk of common web vulnerabilities like SQL injection and cross-site scripting. Furthermore, the lack of file operations and external HTTP requests further minimizes the plugin's attack surface in these areas. The vulnerability history shows no known CVEs, indicating a clean track record and suggesting the developers are proactive in addressing security concerns. The taint analysis showing zero flows with unsanitized paths further reinforces the plugin's secure coding practices.
Despite the overwhelmingly positive findings, there is a single shortcode identified as an entry point. While the static analysis reports no unprotected entry points (implying it might have an implicit check or is not directly exploitable without further context), the absence of explicit capability checks or nonce checks on this shortcode (or any other entry point, as none are listed) is a potential concern. In scenarios where this shortcode might interact with user-provided data or perform sensitive operations, the lack of these standard WordPress security mechanisms could introduce vulnerabilities. However, given the overall lack of any identified issues in SQL, output, taint, or vulnerability history, this concern is minimal and likely mitigated by other factors not visible in this snapshot.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
Dreamy Tags Security Vulnerabilities
Dreamy Tags Release Timeline
Dreamy Tags Code Analysis
Output Escaping
Dreamy Tags Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Dreamy Tags Maintenance & Trust
Maintenance Signals
Community Trust
Dreamy Tags Alternatives
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms
simple-tags
Tags, Categories and WordPress terms are easy with TaxoPress. Add a Tag or Category to Pages, manage your WooCommerce Categories and Tags and more.
WP Categories Widget
wp-categories-widget
Display the list of categories for any taxonomies type (WooCommerce Product Category, Blog Category, Project Category...etc) in sidebar
Beautiful taxonomy filters
beautiful-taxonomy-filters
Supercharge your custom post type archives by letting visitors filter posts by their terms/categories. This plugin handles the whole thing for you!
Post Category Filter (WP Admin)
admin-category-filter
Quickly search and filter categories and taxonomies inside the WordPress admin.
List Products By Category Widget for WooCommerce
woo-products-by-category
Display a list of all the products in a WooCommerce product category with this handy widget.
Dreamy Tags Developer Profile
1 plugin · 0 total installs
How We Detect Dreamy Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dreamy-tags/block.js/wp-content/plugins/dreamy-tags/block.jsdreamy-tags/block.js?ver=dreamy_tags_styles?ver=HTML / DOM Fingerprints
dreamy-tagsdata-catdata-childrendata-tagsdata-exclude-tagsdata-auto-excludedata-min-countdreamy_tags_block[dreamy_tags]