FV Top Level Categories Security & Risk Analysis

wordpress.org/plugins/fv-top-level-cats

This is a fix of Top Level Categories plugin for Wordpress 3.1. and above.

20K active installs v1.9.1 PHP + WP 3.2.1+ Updated Sep 3, 2025
categoriespermalink
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FV Top Level Categories Safe to Use in 2026?

Generally Safe

Score 100/100

FV Top Level Categories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "fv-top-level-cats" v1.9.1 plugin exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits potential avenues for exploitation. Furthermore, the code analysis reveals a complete absence of dangerous functions, raw SQL queries, unescaped output, and file operations, all of which are critical indicators of robust secure coding practices. The presence of a nonce check adds another layer of protection for any potential, though currently absent, interactive elements.

The taint analysis results are equally positive, showing no identified flows with unsanitized paths, further reinforcing the plugin's secure state. The vulnerability history is also clean, with no recorded CVEs, indicating a consistent history of secure development or effective patching by maintainers. The plugin's strengths lie in its minimal attack surface and diligent application of secure coding principles, such as prepared statements and output escaping.

While the current data suggests a very low risk, the complete lack of any identified entry points is unusual for a functional plugin. This could imply that the plugin's functionality is entirely passive or managed through means not captured by this specific static analysis. However, based solely on the provided data, the plugin appears to be very secure.

Vulnerabilities
None known

FV Top Level Categories Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FV Top Level Categories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

FV Top Level Categories Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actioncreated_categorytop-level-cats.php:15
actionedited_categorytop-level-cats.php:16
actiondelete_categorytop-level-cats.php:17
actioninittop-level-cats.php:30
filtercategory_rewrite_rulestop-level-cats.php:53
filtertemplate_redirecttop-level-cats.php:106
filterquery_varstop-level-cats.php:130
filterrequesttop-level-cats.php:137
filtercategory_linktop-level-cats.php:149
filterpost_link_categorytop-level-cats.php:180
filterpost_link_categorytop-level-cats.php:226
filterget_the_categoriestop-level-cats.php:263
actionfv_top_level_categorytop-level-cats.php:267
actionadmin_menutop-level-cats.php:282
actioninittop-level-cats.php:283
Maintenance & Trust

FV Top Level Categories Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 3, 2025
PHP min version
Downloads248K

Community Trust

Rating88/100
Number of ratings23
Active installs20K
Developer Profile

FV Top Level Categories Developer Profile

FolioVision

19 plugins · 48K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
1121 days
View full developer profile
Detection Fingerprints

How We Detect FV Top Level Categories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- For Debugging --><!-- For Debugging --><!-- For Debugging -->
FAQ

Frequently Asked Questions about FV Top Level Categories