
Easy Taxonomy Support Security & Risk Analysis
wordpress.org/plugins/easy-taxonomy-supportUse post tags and categories with pages and custom post types.
Is Easy Taxonomy Support Safe to Use in 2026?
Generally Safe
Score 85/100Easy Taxonomy Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'easy-taxonomy-support' v1.0.2 plugin exhibits a generally positive security posture due to the absence of any known vulnerabilities or critical code signals. The static analysis indicates a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for all SQL queries and avoiding dangerous functions, file operations, external HTTP requests, and bundled libraries. This suggests a developer who is conscious of secure coding principles.
However, a significant concern arises from the complete lack of output escaping. With 3 total outputs identified, the fact that 0% are properly escaped presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data is displayed without proper sanitization, an attacker could inject malicious scripts. Additionally, the absence of nonce checks and capability checks across all identified entry points, although the attack surface is currently zero, means that if any new entry points are introduced in future versions without these security measures, they would be immediately vulnerable to various attacks, including CSRF and unauthorized actions.
In conclusion, while the plugin is currently free from known vulnerabilities and demonstrates strong practices in SQL handling and attack surface minimization, the critical deficiency in output escaping and the lack of authentication checks on potential entry points present clear and present risks. The lack of historical vulnerabilities is a positive sign, but it does not mitigate the identified code-level weaknesses. Addressing the unescaped output is paramount to improving the plugin's security.
Key Concerns
- Unescaped output detected
- Missing capability checks on entry points
- Missing nonce checks on entry points
Easy Taxonomy Support Security Vulnerabilities
Easy Taxonomy Support Release Timeline
Easy Taxonomy Support Code Analysis
Output Escaping
Easy Taxonomy Support Attack Surface
WordPress Hooks 7
Maintenance & Trust
Easy Taxonomy Support Maintenance & Trust
Maintenance Signals
Community Trust
Easy Taxonomy Support Alternatives
Archive Post Order Plus
archive-post-order-plus
A plugin that sets the display order of posts. 投稿の表示順を設定するプラグイン。
Category Search Explorer
category-search-explorer
A powerful and user-friendly category search tool for WordPress. Perfect for sites with extensive categories, tags, or custom taxonomies.
TechWithNavi Pages Taxonomy Manager
pages-taxonomy-manager
Manage Categories and Tags for WordPress Pages.
Taxonomy Extender For Categories and Tags
taxonomy-extender
Adds category and tag support to pages, and extends the default WordPress Categories and Tag widgets to allow excluding specific categories and tags.
Post Tags and Categories for Pages
post-tags-and-categories-for-pages
Adds the built in WordPress categories and tags to your pages.
Easy Taxonomy Support Developer Profile
1 plugin · 10 total installs
How We Detect Easy Taxonomy Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-taxonomy-support/css/ezts-admin.min.csseasy-taxonomy-support/css/ezts-admin.min.css?ver=HTML / DOM Fingerprints
wrapupdatedfadeezts-form<!-- We're going to run this a second time here -->data-settings-updatedezts_options