
Promociones TAP Security & Risk Analysis
wordpress.org/plugins/promociones-tapPlugin para publicacion de promociones y/o publicidad.
Is Promociones TAP Safe to Use in 2026?
Generally Safe
Score 85/100Promociones TAP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "promociones-tap" plugin v1.0.0 exhibits a concerning security posture primarily due to its unprotected entry points and potential for critical vulnerabilities identified in taint analysis. While the plugin demonstrates some good practices, such as using prepared statements for most SQL queries and including nonce and capability checks, the presence of two AJAX handlers without authentication is a significant weakness. Furthermore, the taint analysis revealing two flows with unsanitized paths, though not reaching critical severity, suggests a high risk of potential injection attacks if these flows are exploited. The absence of any known vulnerabilities in its history is positive, indicating that the developers may be attentive or that the plugin hasn't been a target. However, this cannot overshadow the immediate risks identified in the code.
Key Concerns
- AJAX handlers without authentication
- Taint flows with unsanitized paths (High severity)
- Use of unserialize function
- Output escaping is not fully implemented
Promociones TAP Security Vulnerabilities
Promociones TAP Release Timeline
Promociones TAP Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Promociones TAP Attack Surface
AJAX Handlers 2
WordPress Hooks 66
Maintenance & Trust
Promociones TAP Maintenance & Trust
Maintenance Signals
Community Trust
Promociones TAP Alternatives
Denakop Plugin
denakop
This plugin is the easiest way to implement Denakop's TAG on your website. Save time and start making money with our platform.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Promociones TAP Developer Profile
5 plugins · 80 total installs
How We Detect Promociones TAP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/promociones-tap/assets/css/admin.css/wp-content/plugins/promociones-tap/assets/js/admin.js/wp-content/plugins/promociones-tap/public/js/promociones-tap.jsassets/js/promociones-tap.jspromociones-tap/assets/css/admin.css?ver=promociones-tap/assets/js/admin.js?ver=promociones-tap/public/js/promociones-tap.js?ver=HTML / DOM Fingerprints
Promociones_TAPPromociones_TAP_Options_FrameworkPromocion_Post_Type