Fewer Tags Free Security & Risk Analysis

wordpress.org/plugins/fewer-tags

This plugin minimizes the effect of having too many tags by setting a minimum number of posts needed for a tag to be “live” on your site.

200 active installs v1.5.1 PHP 7.4+ WP 6.2+ Updated Mar 19, 2026
seotagtags
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fewer Tags Free Safe to Use in 2026?

Generally Safe

Score 100/100

Fewer Tags Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "fewer-tags" plugin version 1.5.1 exhibits a strong security posture based on the provided static analysis. There are no identified attack surface entry points, dangerous functions, or external HTTP requests. The complete absence of SQL queries not using prepared statements and the lack of file operations further contribute to a secure design. The plugin also has no recorded vulnerability history, indicating a consistent track record of security.

However, the analysis does highlight a significant concern: zero percent of output is properly escaped. With three total outputs identified, this means all user-facing output is potentially vulnerable to Cross-Site Scripting (XSS) attacks. Although there are no identified taint flows or known CVEs, this unescaped output represents a direct and present risk. The absence of capability checks and nonce checks on potential (though currently unmanifested) entry points also leaves room for theoretical vulnerabilities if new entry points were introduced without proper security measures.

In conclusion, the "fewer-tags" plugin has a robust foundation with no critical vulnerabilities detected in its architecture or historical data. The primary weakness lies in the universal lack of output escaping, which introduces a significant XSS risk. Addressing this specific area is paramount to improving the plugin's overall security.

Key Concerns

  • No output escaping
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Fewer Tags Free Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fewer Tags Free Release Timeline

v1.5.1Current
v1.5
v1.4.1
v1.4
v1.3.3
v1.3.2
v1.3
v1.2
Code Analysis
Analyzed Mar 16, 2026

Fewer Tags Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Fewer Tags Free Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedsrc\class-plugin.php:35
actioninitsrc\class-plugin.php:36
Maintenance & Trust

Fewer Tags Free Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 19, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs200
Developer Profile

Fewer Tags Free Developer Profile

Progress Planner

6 plugins · 10K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Fewer Tags Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
fewer-tags.css?ver=fewer-tags.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Fewer Tags Free