
Empty Tags Remover Security & Risk Analysis
wordpress.org/plugins/empty-tags-removerReally simple plugin. It just removes all your empty tags on demand.
Is Empty Tags Remover Safe to Use in 2026?
Generally Safe
Score 91/100Empty Tags Remover has a strong security track record. Known vulnerabilities have been patched promptly.
The "empty-tags-remover" plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The presence of a nonce check is also a positive indicator of security awareness.
However, a significant concern arises from its vulnerability history. The plugin has a known CVE, specifically a medium-severity Cross-site Scripting (XSS) vulnerability. While this vulnerability is currently unpatched, the fact that it's marked as 'unpatched' in the historical data (even though the 'currently unpatched' count is 0) suggests a potential for future risks if patches are not consistently applied. The lack of capability checks is another area that could be improved, as it means that any authenticated user could potentially interact with the plugin's limited functionalities without specific permissions, although the current limited attack surface mitigates immediate risk.
In conclusion, while the plugin's core code appears to be relatively secure with a small attack surface and good data handling practices, the past XSS vulnerability and the absence of capability checks are noteworthy weaknesses. Developers should ensure that all past vulnerabilities are addressed and consider implementing capability checks to further harden the plugin against potential future exploits.
Key Concerns
- Known medium XSS vulnerability
- Missing capability checks
Empty Tags Remover Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Empty Tags Remover <= 1.0 - Reflected Cross-Site Scripting
Empty Tags Remover Code Analysis
Output Escaping
Empty Tags Remover Attack Surface
WordPress Hooks 1
Maintenance & Trust
Empty Tags Remover Maintenance & Trust
Maintenance Signals
Community Trust
Empty Tags Remover Alternatives
Bulk Edit YOAST SEO fields in Spreadsheet
wp-sheet-editor-yoast-seo
Bulk Edit posts, pages, and WooCommerce products YOAST SEO fields using a spreadsheet.
Posts Columns Manager
posts-columns-manager
Did you ever want to add some custom columns to the posts overview page?
Edit Lock
edit-lock
Disable page editing on selected pages, to protect the pages from accidental or unwanted changes that might break your site.
Tabs in Post Editor
tabs-in-post-editor
Write code in the WP post editor? Hate not being able to use [tab]s? Now you can.
Filter Admin Published Default
filter-admin-published-default
Enables all public post types (posts, pages, etc) in wp-admin to show the Published filter by default.
Empty Tags Remover Developer Profile
3 plugins · 150 total installs
How We Detect Empty Tags Remover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrap