Merge Tags Security & Risk Analysis

wordpress.org/plugins/merge-tags

Adds a new form on the tag management screen that lets you merge and replace tags and categories.

40 active installs v1.2 PHP + WP 3.0+ Updated Dec 2, 2010
admincategorymanagementtagterm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Merge Tags Safe to Use in 2026?

Generally Safe

Score 85/100

Merge Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The plugin "merge-tags" v1.2 demonstrates a strong security posture based on the provided static analysis. The absence of any identifiable attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits potential entry vectors for malicious actors. Furthermore, the code analysis reveals excellent development practices, with a complete absence of dangerous functions, raw SQL queries, and unescaped output. The presence of nonce and capability checks indicates an understanding of WordPress security fundamentals. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a well-maintained and secure codebase. However, the static analysis did not report on any taint flows, which is unusual. While the absence of critical or high severity taint flows is positive, the reported 0 total flows analyzed might indicate limitations in the analysis tool itself or that the plugin's functionality is too simple to trigger such analyses. This lack of detailed taint analysis, though not a direct vulnerability, is a minor concern as it limits the completeness of the security review. Overall, this plugin appears to be very secure, with minimal risks.

Vulnerabilities
None known

Merge Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Merge Tags Release Timeline

v1.1.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Merge Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Merge Tags Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionload-edit-tags.phpmerge-tags.php:32
actionload-edit-tags.phpmerge-tags.php:33
actionadmin_enqueue_scriptsmerge-tags.php:34
Maintenance & Trust

Merge Tags Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedDec 2, 2010
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Merge Tags Developer Profile

scribu

24 plugins · 28K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
4851 days
View full developer profile
Detection Fingerprints

How We Detect Merge Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/merge-tags/script.js/wp-content/plugins/merge-tags/script.dev.js
Script Paths
/wp-content/plugins/merge-tags/script.js/wp-content/plugins/merge-tags/script.dev.js
Version Parameters
merge-tags/script.js?ver=1.2merge-tags/script.dev.js?ver=1.2

HTML / DOM Fingerprints

JS Globals
mergeTagsL10n
FAQ

Frequently Asked Questions about Merge Tags