
Mass Delete Taxonomies Security & Risk Analysis
wordpress.org/plugins/mass-delete-tagsDeletes all tags (or other taxonomies), handy tool if you want to start over with a quick clean blog.
Is Mass Delete Taxonomies Safe to Use in 2026?
Generally Safe
Score 85/100Mass Delete Taxonomies has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'mass-delete-tags' plugin v4.1.0 presents a mixed security posture. On the positive side, the static analysis indicates a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are all excellent security practices. The presence of a nonce check is also reassuring.
However, a significant concern arises from the output escaping. With 9 total outputs and 0% properly escaped, there is a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no unsanitized paths, this doesn't mitigate the risk of XSS if user-supplied data is directly echoed into the output without sanitization. The vulnerability history, although currently showing no unpatched CVEs, reveals a past medium-severity vulnerability, specifically a Cross-Site Request Forgery (CSRF), suggesting that the plugin has had security issues in the past and might be susceptible to similar or related vulnerabilities if not diligently maintained.
In conclusion, while the plugin boasts a limited attack surface and good practices regarding database and file operations, the lack of output escaping poses a critical risk for XSS. The past CSRF vulnerability also warrants attention. Users should be cautious due to the potential for XSS and ensure the plugin is kept up-to-date, although the current version shows no unpatched CVEs.
Key Concerns
- 0% output escaping
- 1 medium vulnerability in history
Mass Delete Taxonomies Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mass Delete Taxonomies <= 3.0.0 - Cross-Site Request Forgery via mp_plugin_mass_delete_tags_init
Mass Delete Taxonomies Release Timeline
Mass Delete Taxonomies Code Analysis
Output Escaping
Data Flow Analysis
Mass Delete Taxonomies Attack Surface
WordPress Hooks 1
Maintenance & Trust
Mass Delete Taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
Mass Delete Taxonomies Alternatives
Mass Delete Unused Tags
mass-delete-unused-tags
Deletes all unused tags, handy tool if you want to start over with a quick clean blog.
Auto Prune Posts
auto-prune-posts
Auto deletes expires (prunes) posts after a certain amount of time. On a per category basis (single category, or all at once.
WP Bulk Delete
wp-bulk-delete
Delete posts, pages, comments, users, taxonomy terms and meta fields in bulk with different powerful filters and conditions.
Conditional Menus
conditional-menus
This plugin enables you to set conditional menus per posts, pages, categories, archive pages, etc.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Mass Delete Taxonomies Developer Profile
15 plugins · 5K total installs
How We Detect Mass Delete Taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
mass-delete-tags/style.css?ver=HTML / DOM Fingerprints
plugin_tag_taxplugin_tag_validateplugin_tag_action