
RefTagger Toggle Security & Risk Analysis
wordpress.org/plugins/reftagger-toggleAllows disabling Reftagger on a per-page/post basis.
Is RefTagger Toggle Safe to Use in 2026?
Generally Safe
Score 85/100RefTagger Toggle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The reftagger-toggle v0.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has no identified CVEs and no recorded history of vulnerabilities, which is a positive indicator. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices. The very limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further minimizes potential entry points for attackers. However, a significant concern arises from the lack of output escaping. With one output identified and none properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities if any user-supplied data is reflected in the output without sanitization. The absence of nonce and capability checks, while less concerning given the lack of entry points, could become a risk if new entry points are added in future updates without proper security considerations. Overall, the plugin has good foundational security but requires immediate attention to address the unescaped output.
Key Concerns
- Output not properly escaped
RefTagger Toggle Security Vulnerabilities
RefTagger Toggle Release Timeline
RefTagger Toggle Code Analysis
Output Escaping
RefTagger Toggle Attack Surface
WordPress Hooks 6
Maintenance & Trust
RefTagger Toggle Maintenance & Trust
Maintenance Signals
Community Trust
RefTagger Toggle Alternatives
Logos Reftagger
reftagger
Logos Reftagger turns Bible references into links to the verse on Biblia.com and adds tooltips with the text of the verse.
Bible Verse of the Day
bible-verse-of-the-day
Shows the daily inspiring Bible verse or a random Bible verse from DailyVerses.net. In English, Spanish, Portuguese, German, French, Italian, Polish, …
Bible Verse Display
bible-verse-display
Lets you display either the verse of the day from Biblegateway, or a random verse from your favorites.
VerseLinker
verselinker
VerseLinker detects Bible references in WordPress content, converting them into links with tooltips and quick access to verses on Bibliatodo.com.
Bible Verses – Random Bible Verses
bible-verses
Shows random Bible verses as widget or using shortcode.
RefTagger Toggle Developer Profile
8 plugins · 301K total installs
How We Detect RefTagger Toggle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reftagger-toggle/HTML / DOM Fingerprints
_disable_reftagger