Knowledge Tags from Yext Plugin Security & Risk Analysis

wordpress.org/plugins/knowledge-tags-from-yext

The Knowledge Tags from Yext plugin lets you sync your location data other business content from Yext to your WordPress site as well as adding schema.

30 active installs v1.0.5 PHP + WP 2.8+ Updated Jun 9, 2022
contentknowledge-tagsschemaschema-orgyext
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Knowledge Tags from Yext Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Knowledge Tags from Yext Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "knowledge-tags-from-yext" v1.0.5 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, and a high percentage of properly escaped output are all positive indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of stable and secure development.

However, there are a few areas that warrant attention. The plugin lacks nonce checks for its entry points, which is a critical oversight for any plugin interacting with the WordPress core or user input. While the attack surface is currently small, the absence of nonce checks could become a significant risk if new entry points are introduced without proper security measures. The single capability check is also minimal, and depending on the functionality of the shortcode, this might not be sufficient to prevent unauthorized access to sensitive operations.

In conclusion, while the plugin is built on a foundation of good security practices and has no known vulnerabilities, the lack of nonce checks is a notable weakness. This, coupled with a single capability check, presents a potential, albeit currently low, risk. Continued vigilance and the implementation of nonce checks on all user-facing functionalities would further strengthen its security.

Key Concerns

  • Missing nonce checks on entry points
  • Minimal capability checks for functionality
Vulnerabilities
None known

Knowledge Tags from Yext Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Knowledge Tags from Yext Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
38 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped42 total outputs
Attack Surface

Knowledge Tags from Yext Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[yext-data] yext-schema.php:143
WordPress Hooks 5
actionadmin_initsettings.php:75
actionadmin_initsettings.php:76
actionadmin_initsettings.php:77
actionadmin_menusettings.php:228
actionget_footeryext-schema.php:144
Maintenance & Trust

Knowledge Tags from Yext Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 9, 2022
PHP min version
Downloads12K

Community Trust

Rating20/100
Number of ratings1
Active installs30
Developer Profile

Knowledge Tags from Yext Plugin Developer Profile

Yext

4 plugins · 880 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Knowledge Tags from Yext Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/knowledge-tags-from-yext/public/css/yext.css

HTML / DOM Fingerprints

CSS Classes
KTFY_yext_row
Data Attributes
yext-fieldyext-location-id
JS Globals
KTFY_page_location_IdsKTFY_knowlege_tag_dataKTFY_yext_schema_data
Shortcode Output
[yext-data
FAQ

Frequently Asked Questions about Knowledge Tags from Yext Plugin