TAG / Keyword Internal Links Security & Risk Analysis

wordpress.org/plugins/nleilian-guanjc

Batch processing of website keywords and internal links via internal link tag labels. You can set all specified keywords to hyperlink to the official …

100 active installs v1.0.6 PHP 7.4+ WP 5.3+ Updated Mar 14, 2026
tagtag%e5%86%85%e9%93%betag%e6%a0%87%e7%ad%be%ef%bc%8c%e5%85%b3%e9%94%ae%e8%af%8d%e5%86%85%e9%93%be%e5%86%85%e9%93%be
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TAG / Keyword Internal Links Safe to Use in 2026?

Generally Safe

Score 100/100

TAG / Keyword Internal Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "nleilian-guanjc" plugin v1.0.6 exhibits a mixed security posture. On one hand, it demonstrates good practices by having no known CVEs, no bundled libraries, and a low number of dangerous functions. The attack surface, while comprising 7 AJAX handlers, is fully protected by authentication checks, and the majority of SQL queries utilize prepared statements. However, significant concerns arise from the taint analysis, which identified two flows with unsanitized paths classified as high severity. Furthermore, the output escaping is only properly implemented in 44% of cases, leaving a substantial portion of output vulnerable to potential cross-site scripting (XSS) attacks if data is not sanitized downstream. The lack of recorded vulnerabilities in its history could indicate either a lack of past security scrutiny or a genuinely secure history, but the presence of critical taint flows is a more immediate and pressing concern that warrants attention. While the plugin's protected entry points and SQL practices are strengths, the unsanitized taint flows and insufficient output escaping represent critical weaknesses that must be addressed to improve its overall security.

Key Concerns

  • High severity unsanitized taint flows detected
  • Low percentage of properly escaped output
Vulnerabilities
None known

TAG / Keyword Internal Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TAG / Keyword Internal Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
23
113 prepared
Unescaped Output
73
57 escaped
Nonce Checks
23
Capability Checks
0
File Operations
0
External Requests
17
Bundled Libraries
0

SQL Query Safety

83% prepared136 total queries

Output Escaping

44% escaped130 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

9 flows2 with unsanitized paths
neilian (inc\admin\get.php:150)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TAG / Keyword Internal Links Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_tagmanage_get_cate_typeinc\admin\get.php:7
authwp_ajax_tagmanage_get_post_typeinc\admin\get.php:8
authwp_ajax_tagmanage_get_neilianinc\admin\get.php:9
authwp_ajax_tagmanage_get_taginc\admin\get.php:10
authwp_ajax_tagmanage_get_longinc\admin\get.php:11
authwp_ajax_tagmanage_get_vipinc\admin\get.php:12
authwp_ajax_tagmanage_get_keyinc\admin\get.php:13
WordPress Hooks 17
actiontagmanage_cronhookinc\admin\cron.php:7
actiontagmanage_cronhook1inc\admin\cron_tongbu.php:7
actiontagmanage_five_minute_task_hookinc\admin\cron_zhizhu.php:11
filtertagmanage_check1inc\admin\kp.php:8
filtertagmanage_check2inc\admin\kp.php:9
filtertagmanage_check3inc\admin\kp.php:10
filtertagmanage_check4inc\admin\kp.php:11
filtertagmanage_check5inc\admin\kp.php:12
filtertagmanage_check6inc\admin\kp.php:13
filtertagmanage_check7inc\admin\kp.php:14
actioninitinc\common\index.php:9
actionadmin_enqueue_scriptsinc\common\index.php:11
actionadmin_menuinc\common\index.php:13
actionwp_headinc\common\index.php:15
filtercron_schedulesinc\common\index.php:18
actionthe_contentinc\common\index.php:86
actionplugins_loadedtagmanage.php:52

Scheduled Events 3

tagmanage_cronhook
tagmanage_cronhook1
tagmanage_five_minute_task_hook
Maintenance & Trust

TAG / Keyword Internal Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

TAG / Keyword Internal Links Developer Profile

沃之涛

8 plugins · 1K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect TAG / Keyword Internal Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nleilian-guanjc/inc/js/common.js/wp-content/plugins/nleilian-guanjc/inc/css/common.css
Script Paths
/wp-content/plugins/nleilian-guanjc/inc/js/common.js

HTML / DOM Fingerprints

CSS Classes
tagmanage-admin-wrap
HTML Comments
<!-- 标签管理插件 -->
JS Globals
tagmanage_common_params
FAQ

Frequently Asked Questions about TAG / Keyword Internal Links