
Restricted Tags Security & Risk Analysis
wordpress.org/plugins/restrict-tagsUsing this plugin, Administrators can define tags, which are then the only tags visible for Authors, Editors & Contributors when editing a blog po …
Is Restricted Tags Safe to Use in 2026?
Generally Safe
Score 85/100Restricted Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "restrict-tags" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and importantly, there are no unprotected entry points. The code also demonstrates a commitment to secure SQL practices by using prepared statements exclusively, and there are no file operations or external HTTP requests, further reducing potential vulnerabilities.
However, a critical concern arises from the output escaping. With 5 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not adequately sanitized before being displayed to users could be exploited to inject malicious scripts. The lack of nonce checks, while not directly leading to a deduction given the limited entry points, is a weakness that could become problematic if new entry points are added without proper security considerations. The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign, but it doesn't negate the risks identified in the code analysis.
In conclusion, while the plugin's limited attack surface and secure database practices are commendable, the widespread lack of output escaping represents a significant security flaw that requires immediate attention. The absence of historical vulnerabilities is reassuring, but the identified code-level risk of XSS necessitates caution. Addressing the output escaping issue is paramount to improving the plugin's overall security.
Key Concerns
- Unescaped output detected
- No nonce checks on potential entry points
Restricted Tags Security Vulnerabilities
Restricted Tags Code Analysis
Output Escaping
Restricted Tags Attack Surface
WordPress Hooks 2
Maintenance & Trust
Restricted Tags Maintenance & Trust
Maintenance Signals
Community Trust
Restricted Tags Alternatives
Simple Taxonomy Refreshed
simple-taxonomy-refreshed
This plugin provides a no-code facility to manage your taxonomies - either by defining your own or by adding additional function to existing ones.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Restricted Tags Developer Profile
5 plugins · 440 total installs
How We Detect Restricted Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
categorydivtabs-panellist:categorycategorychecklistform-no-cleartaxonomy-<?php echo $taxonomy; ?><?php echo $taxonomy; ?>-all<?php echo $taxonomy; ?>checklistlist:<?php echo $taxonomy?>