
PoolParty Thesaurus Security & Risk Analysis
wordpress.org/plugins/poolparty-thesaurusPoolParty plugin makes websites more understandable. Blogs benefit from linking posts with key terms automatically. The plugin uses SKOS vocabularies
Is PoolParty Thesaurus Safe to Use in 2026?
Generally Safe
Score 85/100PoolParty Thesaurus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The poolparty-thesaurus plugin v2.8 presents a mixed security profile. On the positive side, there's no recorded vulnerability history, suggesting a generally well-maintained codebase. The plugin also has a very small apparent attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. However, significant concerns arise from the static analysis. The presence of the 'exec' function, a dangerous function, immediately flags potential for arbitrary code execution if not handled with extreme care. Furthermore, all analyzed taint flows resulted in unsanitized paths, with two identified as high severity. This indicates that user-supplied data could potentially be used in dangerous operations without proper sanitization, leading to vulnerabilities like command injection or path traversal. The low percentage of properly escaped output (13%) is also a significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities. The complete lack of capability checks for any entry points, though the entry points themselves are zero, suggests that if any were to be introduced, they might be unprotected.
While the plugin's lack of historical vulnerabilities is a strong positive, the static analysis reveals critical areas for improvement. The high severity taint flows and the insufficient output escaping are immediate red flags that require remediation. The use of `exec` also necessitates careful review of how it's implemented. The absence of capability checks, while currently mitigated by the zero attack surface, points to a potential gap in secure development practices for future updates. Overall, the plugin has a solid foundation with no known exploits, but the identified code-level risks, particularly the unsanitized taint flows and output escaping issues, warrant attention to prevent potential exploitation.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- Dangerous functions used (exec)
- Low output escaping coverage
- No capability checks found
PoolParty Thesaurus Security Vulnerabilities
PoolParty Thesaurus Release Timeline
PoolParty Thesaurus Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
PoolParty Thesaurus Attack Surface
WordPress Hooks 14
Maintenance & Trust
PoolParty Thesaurus Maintenance & Trust
Maintenance Signals
Community Trust
PoolParty Thesaurus Alternatives
LH Tools
lh-tools
LH Tools is a wordpress plugin that enables a sparql endpoint for for WordPress sites. This will enable semantic querying of WordPress data.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Tooltips for WordPress
wordpress-tooltips
Add custom tooltip automatically for post's content/title/tag/excerpt/gallery/menu, easily add image / video / audio / social/link tooltips
Heroic Glossary – Block for building Glossaries, Dictionaries and more
heroic-glossary
The best WordPress glossary builder plugin to create and manage your own glossary of terms.
PoolParty Thesaurus Developer Profile
1 plugin · 10 total installs
How We Detect PoolParty Thesaurus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.