
DynamicTags Security & Risk Analysis
wordpress.org/plugins/dynamictagsAdds some useful dynamic-tags for elementor. Requires Elementor > 3.1
Is DynamicTags Safe to Use in 2026?
Generally Safe
Score 91/100DynamicTags has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "dynamictags" v1.4.1 presents a mixed security profile. On the positive side, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. Furthermore, all SQL queries are properly prepared, indicating good practices in database interaction, and there are no identified taint flows with unsanitized paths.
However, there are several areas of concern. The output escaping is only 38% proper, which is a significant weakness. This suggests that user-supplied or dynamic data might not be adequately neutralized before being displayed, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the plugin performs an external HTTP request, which, without further context, could be a vector for various attacks if the target endpoint is compromised or if data is not properly handled during the request or response.
The vulnerability history shows one known medium-severity CVE related to SQL Injection, which has since been patched. While the past SQL injection vulnerability is resolved, the fact that it existed, coupled with the poor output escaping in the current version, suggests a pattern of potential input validation weaknesses. The absence of nonce checks and the limited capability checks (though present on some functions) on certain entry points also warrant caution. Overall, while the attack surface is well-managed, the deficiencies in output escaping and the history of input-related vulnerabilities necessitate careful review and monitoring.
Key Concerns
- Insufficient output escaping
- External HTTP request present
- No nonce checks on entry points
- Past SQL Injection vulnerability (though patched)
DynamicTags Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
DynamicTags <= 1.4.0 - Authenticated (Subscriber+) SQL Injection
DynamicTags Release Timeline
DynamicTags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DynamicTags Attack Surface
Maintenance & Trust
DynamicTags Maintenance & Trust
Maintenance Signals
Community Trust
DynamicTags Alternatives
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
MB Elementor Integration
mb-elementor-integrator
Integrates Meta Box's custom fields with the Elementor page builder via dynamic tags.
Dynamic ACF Repeater for Elementor
dynamic-elementor-acf-repeater
Renders ACF or Secure Custom Fields repeater values in Elementor loop items and loop grids via Dynamic Tags.
Repeaterly – ACF Repeater, Flexible Content & Dynamic Tags for Elementor
repeaterly
Use ACF Repeater, Relationship & Flexible Content fields in Elementor — free Dynamic Tags included. No Elementor Pro needed.
Dynamic Tags for Elementor
dynamic-tags-for-elementor
Supercharge Elementor Free with 100+ custom dynamic tags. Unlocks WooCommerce, ACF, SCF, and advanced system metrics in Elementor.
DynamicTags Developer Profile
5 plugins · 62K total installs
How We Detect DynamicTags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dynamictags/Admin/js/main.js/wp-content/plugins/dynamictags/Admin/js/main.jsdynamictags/main.js?ver=HTML / DOM Fingerprints
/wp-json/dynamictags/v1/get_elementor_data