
Term/Tag Cloud Search Security & Risk Analysis
wordpress.org/plugins/search-by-taxonomy-tag-cloud-searchCreates a widget that will present a "Tag Cloud" of terms, and allow you to pick one or more terms to search by.
Is Term/Tag Cloud Search Safe to Use in 2026?
Generally Safe
Score 85/100Term/Tag Cloud Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'search-by-taxonomy-tag-cloud-search' v1.0.1 presents a mixed security posture. On one hand, the absence of known CVEs and its clean vulnerability history are positive indicators, suggesting a generally well-maintained plugin. The complete lack of external HTTP requests, file operations, and a zero attack surface from AJAX, REST API, shortcodes, and cron events further contribute to its security. The plugin also utilizes prepared statements for all SQL queries, which is a robust practice against SQL injection.
However, significant concerns arise from the static code analysis. The presence of the `create_function` makes the plugin vulnerable to arbitrary code execution if an attacker can control the input used by this function. Furthermore, the output escaping is notably poor, with only 15% of outputs properly escaped. This leaves the plugin susceptible to cross-site scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website through user-controllable data. The complete absence of nonce and capability checks on any potential entry points (although none were identified in this analysis) would be a critical concern if any were discovered, but as the attack surface is zero, this is not a direct deduction from the data provided.
In conclusion, while the plugin benefits from a clean history and good practices in SQL handling and external interaction, the critical findings of `create_function` and insufficient output escaping introduce significant security risks that require immediate attention.
Key Concerns
- Use of dangerous function create_function
- Insufficient output escaping (15% proper)
Term/Tag Cloud Search Security Vulnerabilities
Term/Tag Cloud Search Code Analysis
Dangerous Functions Found
Output Escaping
Term/Tag Cloud Search Attack Surface
WordPress Hooks 3
Maintenance & Trust
Term/Tag Cloud Search Maintenance & Trust
Maintenance Signals
Community Trust
Term/Tag Cloud Search Alternatives
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Search Meter
search-meter
Search Meter tracks what your readers are searching for on your site. View full details of recent searches or stats for the last day, week or month.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
WPSSO Core – Complete Schema Markup and Meta Tags
wpsso
Present your content at its best for social sites and search results, no matter how URLs are shared, reshared, messaged, posted, embedded, or crawled.
Term/Tag Cloud Search Developer Profile
3 plugins · 220 total installs
How We Detect Term/Tag Cloud Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-by-taxonomy-tag-cloud-search/css/styles.css/wp-content/plugins/search-by-taxonomy-tag-cloud-search/js/scripts.js/wp-content/plugins/search-by-taxonomy-tag-cloud-search/js/scripts.jssearch-by-taxonomy-tag-cloud-search/css/styles.css?ver=search-by-taxonomy-tag-cloud-search/js/scripts.js?ver=