
Easy Additional Tags Security & Risk Analysis
wordpress.org/plugins/easy-additional-tagsEasy Additional Tags is an update to the much loved Multiple Tags plugin.
Is Easy Additional Tags Safe to Use in 2026?
Generally Safe
Score 100/100Easy Additional Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-additional-tags" v4.2.2 plugin presents a generally good security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a significant strength, suggesting a history of stable and secure development. Furthermore, the plugin demonstrates good practices by implementing nonce checks and capability checks for its AJAX handler, and importantly, all SQL queries are prepared statements, mitigating SQL injection risks.
However, there are areas for improvement. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, represent a potential risk. This indicates that user-supplied data might be processed in a way that could lead to unexpected behavior or security issues if not handled with extreme care, especially in file operations where unsanitized paths can lead to directory traversal vulnerabilities. The output escaping, while decent at 63%, still leaves a portion of outputs unescaped, potentially opening the door to cross-site scripting (XSS) vulnerabilities if untrusted data is reflected without proper sanitization.
Overall, the plugin appears to be developed with security in mind, evidenced by the lack of vulnerabilities and the use of prepared statements and authentication checks. The primary concerns revolve around the handling of paths in the taint analysis and the percentage of unescaped output. Addressing these could further harden the plugin's security.
Key Concerns
- Unsanitized paths in taint analysis
- Unescaped output identified
Easy Additional Tags Security Vulnerabilities
Easy Additional Tags Release Timeline
Easy Additional Tags Code Analysis
Output Escaping
Data Flow Analysis
Easy Additional Tags Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Easy Additional Tags Maintenance & Trust
Maintenance Signals
Community Trust
Easy Additional Tags Alternatives
Multiple Tags
multiple-tags
Through this plugin, user can able to combine the repeated tags under the single group tag name
Page Tagger
page-tagger
Page Tagger is a Wordpress plugin which lets you tag your pages just like you do with your posts. It adds a tagging widget in the page-editing view in …
TagPages
tagpages
Adds post-tags functionality for pages.
Already Existing Tags
already-existing-tags
Looks for already existing tags within your posts.
ESV CrossReference Tool
esv-crossref
The ESV CrossReference Tool is a free resource created to make it easy to feature the text of the ESV Bible on your blog, personal website, or church …
Easy Additional Tags Developer Profile
2 plugins · 10 total installs
How We Detect Easy Additional Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-additional-tags/easy-additional-tags-backup.php/wp-content/plugins/easy-additional-tags/easy-additional-tags.phpeasy-additional-tags/easy-additional-tags.php?ver=HTML / DOM Fingerprints
easy_additional_tags_plugin_versioneasy_additional_tags_default_group_sizeeasy_additional_tags_default_group_numbereasy_additional_tags_filename_keywords_tags_vareasy_additional_tags_head_text1easy_additional_tags_head_text2+28 more