
DxTag – SEO-Boosting WooCommerce Listing Generator Security & Risk Analysis
wordpress.org/plugins/dxtag-auto-listingsCreate Virtual SEO Landing Pages effortlessly, avoiding duplicate data, manual categorization, and driving more traffic from search engines
Is DxTag – SEO-Boosting WooCommerce Listing Generator Safe to Use in 2026?
Generally Safe
Score 92/100DxTag – SEO-Boosting WooCommerce Listing Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dxtag-auto-listings plugin v1.0.5 exhibits a generally good security posture, with no known CVEs and a lack of critical taint flows. The plugin effectively utilizes prepared statements for all SQL queries and demonstrates a commitment to capability checks and nonce verification for its entry points. The static analysis indicates that all identified REST API routes and AJAX handlers are protected by permission callbacks or nonce checks. This suggests a thoughtful approach to securing user-facing functionalities.
However, there are areas for improvement. The presence of the `ini_set` function, while not inherently a vulnerability, can sometimes be a risk if not used carefully, potentially allowing for unexpected changes to PHP configurations. Furthermore, the output escaping is only properly handled in 43% of instances, indicating a moderate risk of Cross-Site Scripting (XSS) vulnerabilities. While no immediate critical risks are apparent from the taint analysis or vulnerability history, the unescaped output represents a potential attack vector that should be addressed.
Overall, the plugin is built with several security best practices in mind, particularly regarding database interactions and access control. The absence of historical vulnerabilities is a positive sign. Nevertheless, the moderate level of unescaped output warrants attention to prevent potential XSS flaws. Addressing this weakness would further solidify the plugin's security.
Key Concerns
- Moderate unescaped output (43% proper)
- Presence of dangerous function (ini_set)
DxTag – SEO-Boosting WooCommerce Listing Generator Security Vulnerabilities
DxTag – SEO-Boosting WooCommerce Listing Generator Release Timeline
DxTag – SEO-Boosting WooCommerce Listing Generator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
DxTag – SEO-Boosting WooCommerce Listing Generator Attack Surface
REST API Routes 1
WordPress Hooks 13
Maintenance & Trust
DxTag – SEO-Boosting WooCommerce Listing Generator Maintenance & Trust
Maintenance Signals
Community Trust
DxTag – SEO-Boosting WooCommerce Listing Generator Alternatives
All In One SEO Pack for WooCommerce
woocommerce-all-in-one-seo-pack
Manage All in One SEO Pack meta details for WooCommerce Products within the Add/Edit Products view within the WordPress Administration.
Premmerce SEO for WooCommerce
woo-seo-addon
Premmerce SEO for WooCommerce plugin extends the functionality of WooCommerce microdata management.
Expand Tabs for WooCommerce
woocommerce-extend-tabs
Expand the tabs in the single-product page.
Big SEO Programmatic
knr-pseo-generator
Generate thousands of SEO pages from CSV. The #1 Programmatic SEO bulk page generator for WordPress — free, unlimited, no code needed.
Category collapser SEO for WooCommerce
category-collapser-seo-for-woocommerce
Improve the SEO of your WooCommerce categories
DxTag – SEO-Boosting WooCommerce Listing Generator Developer Profile
6 plugins · 710 total installs
How We Detect DxTag – SEO-Boosting WooCommerce Listing Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dxtag-auto-listings/admin/css/guaven_dxtag-admin.cssguaven_dxtag-admin.css?ver=HTML / DOM Fingerprints
guaven_dxtag<!-- Onboarding Explanation Section --><!-- Ruleset Meta Box -->data-rule-idguaven_dxtag_ajax_object[dxtag_listing