LH User Taxonomies Security & Risk Analysis

wordpress.org/plugins/lh-user-taxonomies

Simplify the process of adding support for custom taxonomies for Users. Just use register_taxonomy and everything else is taken care of.

300 active installs v1.61 PHP + WP 4.0+ Updated Mar 21, 2021
custom-taxonomyregister_taxonomytaxonomyuserusers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH User Taxonomies Safe to Use in 2026?

Generally Safe

Score 85/100

LH User Taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "lh-user-taxonomies" plugin v1.61 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the lack of dangerous functions are positive indicators. The plugin also demonstrates good practices by utilizing prepared statements for all its SQL queries and incorporating a reasonable number of capability checks and a nonce check, suggesting an effort to secure its operations. However, there are areas for improvement. The presence of one flow with an unsanitized path, even though not classified as critical or high severity, warrants attention as it represents a potential entry point for unexpected behavior or subtle vulnerabilities. Furthermore, the output escaping is only properly handled in 61% of cases, leaving a significant portion of output potentially vulnerable to cross-site scripting (XSS) if user-supplied data is not sufficiently sanitized before being displayed. The plugin's minimal attack surface and lack of external dependencies are also strengths.

Key Concerns

  • Unsanitized path flow found
  • Insufficient output escaping (39% not properly escaped)
Vulnerabilities
None known

LH User Taxonomies Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LH User Taxonomies Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
19
30 escaped
Nonce Checks
1
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

61% escaped49 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
set_user_column_values (lh-user-taxonomies.php:172)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LH User Taxonomies Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionregistered_taxonomylh-user-taxonomies.php:732
filterregister_taxonomy_argslh-user-taxonomies.php:735
actionadmin_menulh-user-taxonomies.php:738
filterparent_filelh-user-taxonomies.php:739
actionshow_user_profilelh-user-taxonomies.php:742
actionedit_user_profilelh-user-taxonomies.php:743
actionpersonal_options_updatelh-user-taxonomies.php:744
actionedit_user_profile_updatelh-user-taxonomies.php:745
actionuser_registerlh-user-taxonomies.php:746
filtersanitize_userlh-user-taxonomies.php:749
filtermanage_users_columnslh-user-taxonomies.php:752
actionmanage_users_custom_columnlh-user-taxonomies.php:753
actionpre_user_querylh-user-taxonomies.php:754
filterviews_userslh-user-taxonomies.php:757
actionadmin_initlh-user-taxonomies.php:758
actionadmin_initlh-user-taxonomies.php:761
actiondeleted_userlh-user-taxonomies.php:764
actionplugins_loadedlh-user-taxonomies.php:790
Maintenance & Trust

LH User Taxonomies Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 21, 2021
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings8
Active installs300
Developer Profile

LH User Taxonomies Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH User Taxonomies

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-user-taxonomies/lh-user-taxonomies.php
Version Parameters
lh-user-taxonomies.php?ver=1.61

HTML / DOM Fingerprints

Data Attributes
name="lh_uts-id="lh_uts-
FAQ

Frequently Asked Questions about LH User Taxonomies