
NC Taxonomy Meta Security & Risk Analysis
wordpress.org/plugins/nc-taxonomy-metaNC Taxonomy Meta allows you to add custom meta fields to your wordpress taxonomies.
Is NC Taxonomy Meta Safe to Use in 2026?
Generally Safe
Score 85/100NC Taxonomy Meta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nc-taxonomy-meta" plugin version 1.0.2 presents a concerning security posture due to several significant vulnerabilities identified in the static analysis. While there are no known CVEs associated with this plugin, the code itself reveals critical areas of weakness. A primary concern is the presence of an unprotected AJAX handler, which represents a direct attack vector for unauthenticated users. Furthermore, the extensive use of raw SQL queries without prepared statements (100% of 12 queries) is a major risk, potentially leading to SQL injection vulnerabilities. The taint analysis also highlights two high-severity flows with unsanitized paths, indicating potential for privilege escalation or data manipulation if these paths are exploited.
While the plugin does implement one nonce check, the absence of capability checks on any entry points and the low percentage of properly escaped output (19%) are significant drawbacks. The lack of vulnerability history could indicate either a well-maintained plugin or simply a lack of prior security analysis. However, relying on the absence of historical vulnerabilities is not a robust security strategy. The plugin's strengths are its minimal attack surface in terms of entry points (excluding the unprotected AJAX handler) and the absence of file operations or external HTTP requests. Despite these few positives, the identified risks, particularly the unprotected AJAX handler and widespread use of raw SQL, require immediate attention and mitigation.
Key Concerns
- Unprotected AJAX handler
- 100% of SQL queries use raw SQL
- 2 high severity taint flows
- Low output escaping percentage (19%)
- No capability checks on entry points
NC Taxonomy Meta Security Vulnerabilities
NC Taxonomy Meta Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NC Taxonomy Meta Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
NC Taxonomy Meta Maintenance & Trust
Maintenance Signals
Community Trust
NC Taxonomy Meta Alternatives
NC Taxonomy Meta Developer Profile
3 plugins · 100 total installs
How We Detect NC Taxonomy Meta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nc-taxonomy-meta/css/nc-taxonomy-meta.css/wp-content/plugins/nc-taxonomy-meta/js/nc-taxonomy-meta.js/wp-content/plugins/nc-taxonomy-meta/js/nc-taxonomy-meta.jsnc-taxonomy-meta/css/nc-taxonomy-meta.css?ver=nc-taxonomy-meta/js/nc-taxonomy-meta.js?ver=HTML / DOM Fingerprints
nc_taxonomy_meta_submitnc_taxonomy_noncenc_taxonomy_meta_settings_page