
DX-auto-tags Security & Risk Analysis
wordpress.org/plugins/dx-auto-tags自动搜索自定义的标签列表,如果文章内容包含该文本,则自动添加文章标签.
Is DX-auto-tags Safe to Use in 2026?
Generally Safe
Score 85/100DX-auto-tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dx-auto-tags" plugin v1.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also demonstrates good practice by using prepared statements for all SQL queries and avoiding external HTTP requests and file operations. However, a significant concern arises from the static analysis indicating that 100% of its output is not properly escaped, exposing users to potential Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, which could lead to injection-type attacks if data is not properly handled before being used in sensitive operations.
The plugin's vulnerability history is clean, with no known CVEs. This is a positive indicator of past security efforts or a lack of prior exploitation, but it does not mitigate the risks identified in the current code analysis. The absence of capability checks and nonce checks, while not directly exploitable given the lack of entry points, represents a missed opportunity for robust security hardening. In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and direct SQL injection, the lack of output escaping and the presence of high-severity unsanitized taint flows present notable risks that require immediate attention.
Key Concerns
- High severity taint flows with unsanitized paths
- Output escaping is missing on all outputs
- No nonce checks on potential entry points
- No capability checks on potential entry points
DX-auto-tags Security Vulnerabilities
DX-auto-tags Release Timeline
DX-auto-tags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DX-auto-tags Attack Surface
WordPress Hooks 4
Maintenance & Trust
DX-auto-tags Maintenance & Trust
Maintenance Signals
Community Trust
DX-auto-tags Alternatives
Already Existing Tags
already-existing-tags
Looks for already existing tags within your posts.
Automatic Post Tagger
automatic-post-tagger
Adds relevant taxonomy terms to posts using a keyword list provided by the user.
WP AutoTags
wp-autotags
英文:Often publish articles and updates people loves forgets to set tags when editing an article, the article automatically add keywords tag.
SEO SearchTerms Admin
seo-searchterms-admin
This simple plugin will list all the incoming search terms generated by SEO SearchTerms Tagging 2. You will need to have SEO SearchTerms Tagging 2 in …
XHTheme AI Toolbox
xhtheme-ai-toolbox
AI tag extraction, AI image, AI summary, comment generation, AI topic expansion, auto-classification, slug generation and AI content enhancement.
DX-auto-tags Developer Profile
4 plugins · 330 total installs
How We Detect DX-auto-tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dx-auto-tags/icon.pngHTML / DOM Fingerprints
<!-- daxiawp开发的原创插件,任何个人或团体不可擅自更改版权。 -->name="insert-tags"value="新增"name="update-tags"name="delete-tags"name="one-key"value="一键更新"<p>插件介绍:<a href="http://www.daxiawp.com/dx-auto-tags.html" target="_blank">http://www.daxiawp.com/dx-auto-tags.html</a></p><p>wordpress主题请访问<a href="http://www.daxiawp.com" target="_blank">daxiawp</a>,大量大侠wp制作的主题供选择。wordpress定制、仿站、插件开发请联系:<a target="_blank" href="http://wpa.qq.com/msgrd?v=3&uin=1683134075&site=qq&menu=yes"><img border="0" src="http://wpa.qq.com/pa?p=2:1683134075:44" alt="点击这里给我发消息" title="点击这里给我发消息">1683134075</a></p>