DxTag – SEO-Boosting WooCommerce Listing Generator Security & Risk Analysis

wordpress.org/plugins/dxtag-auto-listings

Create Virtual SEO Landing Pages effortlessly, avoiding duplicate data, manual categorization, and driving more traffic from search engines

0 active installs v1.0.5 PHP + WP 5.0.0+ Updated Dec 3, 2024
dynamic-listingspage-generatorseo-boostsmart-collectionswoocommerce-seo
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DxTag – SEO-Boosting WooCommerce Listing Generator Safe to Use in 2026?

Generally Safe

Score 92/100

DxTag – SEO-Boosting WooCommerce Listing Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The dxtag-auto-listings plugin v1.0.5 exhibits a generally good security posture, with no known CVEs and a lack of critical taint flows. The plugin effectively utilizes prepared statements for all SQL queries and demonstrates a commitment to capability checks and nonce verification for its entry points. The static analysis indicates that all identified REST API routes and AJAX handlers are protected by permission callbacks or nonce checks. This suggests a thoughtful approach to securing user-facing functionalities.

However, there are areas for improvement. The presence of the `ini_set` function, while not inherently a vulnerability, can sometimes be a risk if not used carefully, potentially allowing for unexpected changes to PHP configurations. Furthermore, the output escaping is only properly handled in 43% of instances, indicating a moderate risk of Cross-Site Scripting (XSS) vulnerabilities. While no immediate critical risks are apparent from the taint analysis or vulnerability history, the unescaped output represents a potential attack vector that should be addressed.

Overall, the plugin is built with several security best practices in mind, particularly regarding database interactions and access control. The absence of historical vulnerabilities is a positive sign. Nevertheless, the moderate level of unescaped output warrants attention to prevent potential XSS flaws. Addressing this weakness would further solidify the plugin's security.

Key Concerns

  • Moderate unescaped output (43% proper)
  • Presence of dangerous function (ini_set)
Vulnerabilities
None known

DxTag – SEO-Boosting WooCommerce Listing Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DxTag – SEO-Boosting WooCommerce Listing Generator Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

DxTag – SEO-Boosting WooCommerce Listing Generator Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
3 prepared
Unescaped Output
17
13 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

ini_setini_set('memory_limit',$memory_limit);admin/class-guaven_dxtag-admin.php:250

SQL Query Safety

100% prepared3 total queries

Output Escaping

43% escaped30 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_settings (admin/class-guaven_dxtag-admin.php:204)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DxTag – SEO-Boosting WooCommerce Listing Generator Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/app/v1/dx-rule-regenerator/admin/class-guaven_dxtag-admin.php:232
WordPress Hooks 13
actionplugins_loadedincludes/class-guaven_dxtag.php:133
actionadmin_enqueue_scriptsincludes/class-guaven_dxtag.php:153
actionadmin_enqueue_scriptsincludes/class-guaven_dxtag.php:154
actioninitincludes/class-guaven_dxtag.php:155
actionadmin_menuincludes/class-guaven_dxtag.php:156
actionadmin_initincludes/class-guaven_dxtag.php:158
actionadmin_initincludes/class-guaven_dxtag.php:159
actionwpincludes/class-guaven_dxtag.php:160
actionwpincludes/class-guaven_dxtag.php:162
actionadd_meta_boxesincludes/class-guaven_dxtag.php:167
actionsave_postincludes/class-guaven_dxtag.php:168
actiontransition_post_statusincludes/class-guaven_dxtag.php:169
actionrest_api_initincludes/class-guaven_dxtag.php:172
Maintenance & Trust

DxTag – SEO-Boosting WooCommerce Listing Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 3, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DxTag – SEO-Boosting WooCommerce Listing Generator Developer Profile

Guaven Labs

6 plugins · 710 total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
168 days
View full developer profile
Detection Fingerprints

How We Detect DxTag – SEO-Boosting WooCommerce Listing Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dxtag-auto-listings/admin/css/guaven_dxtag-admin.css
Version Parameters
guaven_dxtag-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
guaven_dxtag
HTML Comments
<!-- Onboarding Explanation Section --><!-- Ruleset Meta Box -->
Data Attributes
data-rule-id
JS Globals
guaven_dxtag_ajax_object
Shortcode Output
[dxtag_listing
FAQ

Frequently Asked Questions about DxTag – SEO-Boosting WooCommerce Listing Generator