Hidden Tags Security & Risk Analysis

wordpress.org/plugins/hidden-tags

Hide certain tags/categories from the public

100 active installs v0.1.1 PHP + WP 2.6+ Updated Jan 23, 2010
categorieshiddenhidesecrettags
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hidden Tags Safe to Use in 2026?

Generally Safe

Score 85/100

Hidden Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "hidden-tags" plugin v0.1.1 exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, coupled with the lack of dangerous function calls and file operations, significantly limits its attack surface. Furthermore, all SQL queries are correctly using prepared statements, and there are no recorded vulnerabilities in its history, which suggests a careful development approach. However, a significant concern arises from the output escaping analysis, where 100% of the identified outputs are not properly escaped. This presents a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into these outputs. While the current data shows no taint flows or obvious entry points for such attacks, the lack of escaping remains a weakness that could be exploited if the plugin's functionality evolves or interacts with user input in ways not apparent in this analysis.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Hidden Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hidden Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Hidden Tags Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterget_termshidden-tags.php:123
filterwp_get_object_termshidden-tags.php:124
actionadmin_menuhidden-tags.php:125
Maintenance & Trust

Hidden Tags Maintenance & Trust

Maintenance Signals

WordPress version tested2.7.1
Last updatedJan 23, 2010
PHP min version
Downloads8K

Community Trust

Rating94/100
Number of ratings3
Active installs100
Developer Profile

Hidden Tags Developer Profile

michaeltyson

3 plugins · 160 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hidden Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Hidden Tags