
tags.mowster Security & Risk Analysis
wordpress.org/plugins/mowster-tagsTags suggestions using YQL Yahoo Content Analysis API.
Is tags.mowster Safe to Use in 2026?
Generally Safe
Score 85/100tags.mowster has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mowster-tags plugin v1.71 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping a high percentage of its output. The absence of known vulnerabilities in its history is also a strong indicator of a generally well-maintained plugin.
However, there are significant concerns regarding its attack surface and handling of potentially dangerous operations. The presence of an unprotected AJAX handler is a critical vulnerability, as it represents a direct entry point for attackers without any authentication or authorization checks. Additionally, the use of the `unserialize` function is a known security risk, as it can lead to Remote Code Execution (RCE) if not handled with extreme care and input validation. While taint analysis did not reveal critical or high-severity issues, the existence of flows with unsanitized paths, even if not explicitly critical, warrants caution. The lack of nonce checks on the AJAX handler amplifies the risk associated with that entry point.
In conclusion, while the plugin's history and SQL practices are commendable, the unprotected AJAX handler and the use of `unserialize` represent substantial security weaknesses. These are critical areas that need immediate attention to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- Flows with unsanitized paths
- Missing nonce checks
tags.mowster Security Vulnerabilities
tags.mowster Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
tags.mowster Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
tags.mowster Maintenance & Trust
Maintenance Signals
Community Trust
tags.mowster Alternatives
Page Tagger
page-tagger
Page Tagger is a Wordpress plugin which lets you tag your pages just like you do with your posts. It adds a tagging widget in the page-editing view in …
Smart Tag Insert
smart-tag-insert
Automatically adds most relevant tags to posts selecting them from an admin-defined list.
WP Calais Auto Tagger
calais-auto-tagger
The plugin performs semantic analysis of your posts to suggest tags using Open Calais.
Related Articles by Tag Lite
related-articles-by-tag
With this plugin you can add a list of links to posts having the same tag(s) of the current post.
TagΒee Post Tagger
tagbee-automatic-post-tagging
TagBee is the easy way to add tags to your posts.TagBee works in a simple way: it proposes tags for your content. However, under the hood, TagBee uses …
tags.mowster Developer Profile
2 plugins · 20 total installs
How We Detect tags.mowster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mowster-tags/css/style.css/wp-content/plugins/mowster-tags/js/tags.js/wp-content/plugins/mowster-tags/js/tags.jsmowster-tags/style.css?ver=mowster-tags/js/tags.js?ver=HTML / DOM Fingerprints
mowsterVars