Jam Taxonomy Image Security & Risk Analysis

wordpress.org/plugins/jam-taxonomy-image

Jam Taxonomy Image will help you have a nicer Category/Tag/Custom Post type Page with banner, and have a nice and powerful Taxonomy Widget

10 active installs v1.0 PHP + WP 3.0+ Updated Sep 27, 2015
category-imagecategory-thumbnailtag-imagetaxonomy-thumbnailthumbnail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jam Taxonomy Image Safe to Use in 2026?

Generally Safe

Score 85/100

Jam Taxonomy Image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "jam-taxonomy-image" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified dangerous functions, file operations, external HTTP requests, or SQL queries that are not using prepared statements, which are all positive indicators. The plugin also correctly implements a capability check. However, a significant concern is the complete lack of output escaping for all identified output points. This presents a serious risk of cross-site scripting (XSS) vulnerabilities, as untrusted data could be directly rendered in the browser without sanitization. The plugin also has no nonce checks, which, while not directly indicated as a vulnerability without any entry points utilizing them, is a missed opportunity for security best practices when interacting with the WordPress core.

The vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical or high severity taint flows, suggests that the plugin has not been a target of major vulnerabilities in the past. However, the lack of output escaping is a fundamental security flaw that could lead to vulnerabilities even without historical precedent. In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unescaped output is a critical weakness that requires immediate attention. The absence of historical vulnerabilities is encouraging but does not negate the present risk introduced by the lack of output sanitization.

Key Concerns

  • All output points are unescaped
  • No nonce checks implemented
Vulnerabilities
None known

Jam Taxonomy Image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Jam Taxonomy Image Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 17, 2026

Jam Taxonomy Image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
jam_taxonomy_plugin_options (jam-taxonomy-image.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Jam Taxonomy Image Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menujam-taxonomy-image.php:27
actionadmin_headjam-taxonomy-image.php:98
Maintenance & Trust

Jam Taxonomy Image Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 27, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Jam Taxonomy Image Developer Profile

Jam Viet

6 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jam Taxonomy Image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jam-taxonomy-image/lib/taxonomy-metadata.php/wp-content/plugins/jam-taxonomy-image/lib/widget.php

HTML / DOM Fingerprints

CSS Classes
form-field
HTML Comments
Admin Step 2 (from text above). Step 1. Step 3. +8 more
Data Attributes
title="Choose Taxonomy"title="Taxonomy thumbnail"
JS Globals
wp
FAQ

Frequently Asked Questions about Jam Taxonomy Image