
Post-tag automaton Security & Risk Analysis
wordpress.org/plugins/post-tag-automatonThe post-tag is added automatically if that is found a content when saving post. Moreover, some similar words can be set to a post-tag.
Is Post-tag automaton Safe to Use in 2026?
Generally Safe
Score 85/100Post-tag automaton has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Post Tag Automaton plugin, version 1.0.1, exhibits a mixed security posture. While it demonstrates strengths in avoiding dangerous functions, raw SQL queries, file operations, and external HTTP requests, significant security concerns are present. The most prominent issue is the presence of an unprotected AJAX handler, which constitutes the entire attack surface of the plugin. This direct entry point without authentication or capability checks is a major vulnerability. Additionally, the taint analysis reveals two flows with unsanitized paths, indicating potential for improper handling of data, although the severity is not classified as critical or high in the provided data. The lack of nonce checks further exacerbates the risk associated with the AJAX handler.
The plugin has no recorded vulnerability history, which is a positive indicator of past security diligence. However, this does not negate the immediate risks identified in the static analysis. The absence of known CVEs suggests that either the plugin has not been a target for widespread attacks or vulnerabilities have been promptly addressed in past versions. In conclusion, while the plugin has good practices in some areas, the unprotected AJAX handler and unsanitized data flows represent a significant security weakness that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths (taint analysis)
- Missing nonce checks on AJAX
- No capability checks
Post-tag automaton Security Vulnerabilities
Post-tag automaton Code Analysis
Output Escaping
Data Flow Analysis
Post-tag automaton Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Post-tag automaton Maintenance & Trust
Maintenance Signals
Community Trust
Post-tag automaton Alternatives
Gutena Recent Post Custom Tag
post-featured-tag-block-by-gutena
A WordPress Plugin that adds a custom tag to your recent post like Must Read, Featured, Hot, Top News, Popular etc. It helps you to attract the visito …
Post Tags Widget
post-tags-widget
Display tags for the current post in a widget.
Add Categories And Tags To Pages
add-categories-and-tags-to-pages
WordPress plugin that adds categories and tags to pages.
f(x) Categories Widget
fx-categories-widget
Categories widget with taxonomy option.
Quick Bulk Tags Creator
quick-bulk-tags-creator
Easily add tags in bulk, and easily create a filter function to modifiy the values you insert
Post-tag automaton Developer Profile
8 plugins · 21K total installs
How We Detect Post-tag automaton
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-tag-automaton/languages/post-tag-automaton/style.css?ver=post-tag-automaton/script.js?ver=HTML / DOM Fingerprints
similarcolumn-similartag-similarsimilar_wordsdprintf