
Multiupload In Custom Taxonomy Security & Risk Analysis
wordpress.org/plugins/multiupload-in-custom-taxonomyAdd multiupload custom field in custom taxonomy.
Is Multiupload In Custom Taxonomy Safe to Use in 2026?
Generally Safe
Score 100/100Multiupload In Custom Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multiupload-in-custom-taxonomy v1.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strengths by having a limited attack surface with no identified AJAX handlers or REST API routes exposed without authentication. The presence of nonce and capability checks also indicates an awareness of basic security practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of responsible development or a lack of past scrutiny.
However, significant concerns arise from the static analysis of the codebase. The fact that 0% of SQL queries use prepared statements is a major red flag, opening the door to potential SQL injection vulnerabilities. Coupled with this, 0% of output is properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode which often involves user-generated or dynamic content rendering. The absence of taint analysis results is also noteworthy, as it might mean the analysis tool was not configured to perform it, or that such flows were not detected, which could mask potential issues.
In conclusion, while the plugin's attack surface and vulnerability history are promising, the critical lack of prepared statements for SQL queries and proper output escaping present substantial and immediate security risks. These are fundamental security practices that are currently not being met, demanding careful attention and remediation.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
Multiupload In Custom Taxonomy Security Vulnerabilities
Multiupload In Custom Taxonomy Code Analysis
SQL Query Safety
Output Escaping
Multiupload In Custom Taxonomy Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Multiupload In Custom Taxonomy Maintenance & Trust
Maintenance Signals
Community Trust
Multiupload In Custom Taxonomy Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Custom Taxonomy Order
custom-taxonomy-order-ne
Allows for the ordering of categories and custom taxonomy terms through a simple drag-and-drop interface
Search & Filter
search-filter
Search and Filtering for Custom Posts, Categories, Tags, Taxonomies, Post Dates and Post Types
Multiupload In Custom Taxonomy Developer Profile
4 plugins · 50 total installs
How We Detect Multiupload In Custom Taxonomy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multiupload-in-custom-taxonomy/css/multi-image.css/wp-content/plugins/multiupload-in-custom-taxonomy/js/multi-message.js/wp-content/plugins/multiupload-in-custom-taxonomy/js/multi-message.jsHTML / DOM Fingerprints
of_containerof-save-popupof-save-saveform-tablefield-statusfield-nameAIGolbalMultiuploadOptionsid="of_container"id="of-popup-save"class="of-save-popup"class="of-save-save"id="AIGolbalMultiuploadOptions"id="form-settings"[multiimg]