
SensitiveTagCloud Security & Risk Analysis
wordpress.org/plugins/sensitive-tag-cloudThis wordpress plugin provides a tagcloud that shows tags depending of the current context (e.g. Category, Author, Tag, Post) only.
Is SensitiveTagCloud Safe to Use in 2026?
Use With Caution
Score 63/100SensitiveTagCloud has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "sensitive-tag-cloud" plugin version 1.4.1 presents a mixed security posture. On one hand, it demonstrates good practices by avoiding dangerous functions, using prepared statements for its single SQL query, and not performing file operations or external HTTP requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events also indicates a relatively small attack surface, with no entry points identified as immediately unprotected in the static analysis. However, a significant concern arises from the complete lack of output escaping, meaning all 27 outputs are potentially vulnerable to cross-site scripting (XSS) attacks.
The vulnerability history reveals a known medium severity Cross-Site Request Forgery (CSRF) vulnerability that is currently unpatched. The existence of this historical CSRF issue, coupled with the complete absence of nonce checks in the code, suggests a pattern of insufficient security controls against such attacks. The lack of capability checks further compounds this, as it means that unauthorized users might be able to trigger actions within the plugin that they shouldn't be able to.
Overall, while the plugin has some secure coding habits regarding database interactions and external communication, the critical oversight in output escaping and the unpatched CSRF vulnerability with absent nonce checks pose significant risks. The absence of taint analysis flows is noted, but this may be due to the limited attack surface or the nature of the identified vulnerabilities.
Key Concerns
- Unpatched medium vulnerability (CSRF)
- No output escaping
- No nonce checks
- No capability checks
SensitiveTagCloud Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SensitiveTagCloud <= 1.4.1 - Cross-Site Request Forgery
SensitiveTagCloud Code Analysis
SQL Query Safety
Output Escaping
SensitiveTagCloud Attack Surface
WordPress Hooks 5
Maintenance & Trust
SensitiveTagCloud Maintenance & Trust
Maintenance Signals
Community Trust
SensitiveTagCloud Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Categorized Tag Cloud
categorized-tag-cloud
A cloud with the most used tags in a sidebar widget, filtered by post category.
GS Posts Widget
posts-widget
Best Responsive WordPress Posts Widget Plugin to display latest Posts elegantly.
SensitiveTagCloud Developer Profile
5 plugins · 90 total installs
How We Detect SensitiveTagCloud
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sensitive-tag-cloud/css/sensitive-tag-cloud.css/wp-content/plugins/sensitive-tag-cloud/js/sensitive-tag-cloud.js/wp-content/plugins/sensitive-tag-cloud/js/sensitive-tag-cloud.jssensitive-tag-cloud/css/sensitive-tag-cloud.css?ver=sensitive-tag-cloud/js/sensitive-tag-cloud.js?ver=HTML / DOM Fingerprints
stc-tag-cloudWordPress Plugin SensitiveTagCloud by Rene Ade - http://www.rene-ade.de/inhalte/wordpress-plugin-sensitivetagcloud.htmlstc_widget_options