
Dynamic CTR Security & Risk Analysis
wordpress.org/plugins/dynamic-ctrSimple and lightweight plugin for creating and managing custom taxonomies in WordPress.
Is Dynamic CTR Safe to Use in 2026?
Generally Safe
Score 85/100Dynamic CTR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'dynamic-ctr' plugin v1.1 exhibits a very strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with an unprotected attack surface is a significant strength. The code signals also indicate good development practices, with 100% of SQL queries using prepared statements and all output properly escaped. The presence of nonce and capability checks, even with a limited attack surface, further bolsters its security. Furthermore, the complete lack of any recorded vulnerabilities, past or present, suggests a mature and well-maintained plugin.
The analysis reveals no identified taint flows, dangerous functions, file operations, or external HTTP requests, which are all positive indicators. The only item of note is the inclusion of the 'Select2' bundled library, which could potentially be an outdated version if not actively maintained. However, without specific version information or known vulnerabilities associated with bundled libraries, this is a minor point.
In conclusion, 'dynamic-ctr' v1.1 appears to be a highly secure plugin. Its minimal attack surface and adherence to secure coding practices significantly reduce the risk of common web vulnerabilities. The perfect track record of no known CVEs further reinforces this assessment. The primary, albeit minor, area for attention would be ensuring any bundled libraries are kept up-to-date.
Key Concerns
- Bundled library could be outdated
Dynamic CTR Security Vulnerabilities
Dynamic CTR Release Timeline
Dynamic CTR Code Analysis
Bundled Libraries
Output Escaping
Dynamic CTR Attack Surface
WordPress Hooks 6
Maintenance & Trust
Dynamic CTR Maintenance & Trust
Maintenance Signals
Community Trust
Dynamic CTR Alternatives
JC Submenu
jc-submenu
JC Submenu plugin allows you to automatically populate your navigation menus with custom post_types, taxonomies, or child pages.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Essential Content Types
essential-content-types
Essential Content Types allows you to feature the impressive content through different content/post types on your website just the way you want it.
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
Gravity Forms + Custom Post Types
gravity-forms-custom-post-types
Map your Gravity-Forms-generated posts to a custom post type and/or custom taxonomies.
Dynamic CTR Developer Profile
7 plugins · 140 total installs
How We Detect Dynamic CTR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dynamic-ctr/src/lib/select2/css/select2.min.css/wp-content/plugins/dynamic-ctr/src/lib/select2/js/select2.min.js/wp-content/plugins/dynamic-ctr/src/js/select2-init.jsHTML / DOM Fingerprints
name="kmfdtr_metadata[][tax_name]"name="kmfdtr_metadata[][tax_id]"name="kmfdtr_metadata[][hirarchial]"name="kmfdtr_metadata[][query_var]"name="kmfdtr_metadata[][show_admin_column]"name="kmfdtr_metadata[][post_types]"