
Newer Tag Cloud Security & Risk Analysis
wordpress.org/plugins/newer-tag-cloudA small plugin providing a neat tag cloud feature. Inspired by New Tag Cloud.
Is Newer Tag Cloud Safe to Use in 2026?
Generally Safe
Score 85/100Newer Tag Cloud has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "newer-tag-cloud" plugin version 1.1.2 presents a mixed security profile. On the positive side, it boasts no reported vulnerabilities (CVEs) and a seemingly small attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, all SQL queries utilize prepared statements, a strong indicator of good database security practices. However, several concerning code signals warrant attention. The presence of four instances of the `unserialize` function is a significant red flag, as this function is notoriously dangerous if used with untrusted input, potentially leading to Remote Code Execution (RCE) vulnerabilities. Furthermore, only 16% of output is properly escaped, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks through unsanitized data displayed to users. Taint analysis reveals two flows with unsanitized paths, which, when combined with the `unserialize` function and poor output escaping, indicate a potential for serious security flaws, even if no critical or high severity issues were flagged in this specific analysis. The lack of nonce checks on potential entry points and limited capability checks (only 2) suggest that authentication and authorization mechanisms might be weak, further exacerbating the risks posed by the identified code signals.
Key Concerns
- Presence of 'unserialize' function
- Low output escaping percentage (16%)
- Unsanitized paths in taint flows
- Lack of nonce checks
Newer Tag Cloud Security Vulnerabilities
Newer Tag Cloud Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Newer Tag Cloud Attack Surface
WordPress Hooks 1
Maintenance & Trust
Newer Tag Cloud Maintenance & Trust
Maintenance Signals
Community Trust
Newer Tag Cloud Alternatives
Ultimate Tag Cloud Widget
ultimate-tag-cloud-widget
This plugin aims to be the most configurable tag cloud widget out there, able to suit all your weird tag cloud needs.
Configurable Tag Cloud (CTC)
configurable-tag-cloud-widget
Display a tag cloud customized with your preferences in the sidebar.
Most Popular Tags
most-popular-tags
Most Popular Tags is a plugin that displays your WordPress site's most popular tags, categories and custom taxonomies as a sidebar widget.
Random Tags Cloud Widget
random-tags-cloud-widget
Random Tags Cloud displays your tags by selecting randomly. Of course, you can customize other tag cloud's settings.
Muki Tag Cloud
muki-tag-cloud
Another wordpress tag cloud plugin based on jQCloud, which is creative, beauty and colorful.
Newer Tag Cloud Developer Profile
1 plugin · 0 total installs
How We Detect Newer Tag Cloud
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newer-tag-cloud/admin/css/newer-tag-cloud-admin.css/wp-content/plugins/newer-tag-cloud/admin/js/newer-tag-cloud-admin.js/wp-content/plugins/newer-tag-cloud/public/css/newer-tag-cloud-public.css/wp-content/plugins/newer-tag-cloud/public/js/newer-tag-cloud-public.js/wp-content/plugins/newer-tag-cloud/admin/js/newer-tag-cloud-admin.js/wp-content/plugins/newer-tag-cloud/public/js/newer-tag-cloud-public.jsnewer-tag-cloud/admin/css/newer-tag-cloud-admin.css?ver=newer-tag-cloud/admin/js/newer-tag-cloud-admin.js?ver=newer-tag-cloud/public/css/newer-tag-cloud-public.css?ver=newer-tag-cloud/public/js/newer-tag-cloud-public.js?ver=HTML / DOM Fingerprints
newer-tag-cloud-widgetnewer-tag-cloud-admin-wrapdata-instance-idnewerTagCloud[newertagcloud]