
kakao-tam Security & Risk Analysis
wordpress.org/plugins/kakao-tam카카오 디벨로퍼스에서 제공하는 카카오 로그인, 카카오톡 공유하기, 카카오톡 채널 친구추가/채팅, 카카오 내비, 카카오 맵 기능을 연동한 플러그인
Is kakao-tam Safe to Use in 2026?
Generally Safe
Score 100/100kakao-tam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kakao-tam" plugin v1.8.10 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a generally well-maintained codebase. However, the static analysis reveals significant areas of concern, particularly regarding the attack surface. The presence of two AJAX handlers without authentication checks is a notable weakness, potentially exposing the plugin to unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis indicates two flows with unsanitized paths, although these are not classified as critical or high severity, they still represent a risk of unintended data handling. The lack of nonce checks on these unprotected AJAX handlers compounds this risk. The plugin also has a moderate percentage of improperly escaped outputs, which could lead to cross-site scripting (XSS) vulnerabilities if malicious data is processed and displayed without proper sanitization. The absence of capability checks on these specific entry points is a missed opportunity for robust access control.
While the plugin has a clean vulnerability history, the current static analysis findings warrant attention. The unprotected AJAX handlers are the most immediate concern. The taint flows, even if not critical, highlight the need for thorough input validation and sanitization. The imperfect output escaping also increases the risk of XSS. The plugin's strengths lie in its SQL query handling and lack of past vulnerabilities, but these are overshadowed by the identified security gaps in its entry points and data handling. A proactive approach to addressing the unprotected AJAX endpoints and improving output escaping is recommended.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Improperly escaped output (39% of total)
- Missing nonce checks on AJAX handlers
- Capability checks missing on AJAX handlers
kakao-tam Security Vulnerabilities
kakao-tam Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
kakao-tam Attack Surface
AJAX Handlers 2
Shortcodes 8
WordPress Hooks 10
Maintenance & Trust
kakao-tam Maintenance & Trust
Maintenance Signals
Community Trust
kakao-tam Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
kakao-tam Developer Profile
1 plugin · 200 total installs
How We Detect kakao-tam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kakao-tam/style.css/wp-content/plugins/kakao-tam/script_function.js/wp-content/plugins/kakao-tam/script_admin_function.jshttps://t1.kakaocdn.net/kakao_js_sdk/2.4.0/kakao.min.jskakao-tam-stylekakao_tam_script_functionHTML / DOM Fingerprints
2023.02.26 Dom 객체를 다루는 편집기 플러그인에서 html 밖에 객체 추가 시, 에러 발생하여 include 'script_init.php'; 에는 서버사이드 스크립트만 추가2023.02.26 Dom 객체를 다루는 편집기 플러그인에서 html 밖에 객체 추가 시, 에러 발생하여 wp_head 에 스크립틀릿 방식 클라이언트 스크립트 추가2023.08.27 플러그인과 테마에 따른 로그인 URI 변경 시, 리다이렉트 URI도 변경 되도록 wp_login_url() 함수 사용2023.09.01 wp_enqueue_script() 함수에 integrity 처리가 되어 있지 않아, 직접 스크립트 추가+1 moreKakaoajax_objectkakao_initloginWithKakao/wp-json/kakao-tam/