
SF Generate Tags Security & Risk Analysis
wordpress.org/plugins/sf-generate-tagsGenerate tags for posts from images or/and post text.
Is SF Generate Tags Safe to Use in 2026?
Generally Safe
Score 85/100SF Generate Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sf-generate-tags plugin v1.4.1 exhibits a concerning security posture due to a critical lack of proper input validation and authorization. While the plugin boasts no known vulnerabilities in its history and utilizes prepared statements for its SQL queries, this is overshadowed by significant risks identified in the static analysis. The presence of an unprotected AJAX handler represents a direct entry point for potential attacks, as there are no nonces or capability checks in place. Furthermore, the complete absence of output escaping for any identified outputs means that any data processed through these AJAX handlers could be susceptible to cross-site scripting (XSS) vulnerabilities, even if the data itself is not directly user-provided.
Despite the absence of dangerous functions, file operations, or external HTTP requests, and a clean vulnerability history suggesting diligent patching or a lack of past issues, the current implementation is far from secure. The 100% unescaped output and the unprotected AJAX handler are major red flags. The lack of any recorded vulnerabilities could be interpreted positively, but it's also possible that these weaknesses have simply not been exploited or discovered yet. The plugin needs immediate attention to address the unprotected AJAX endpoint and implement robust output escaping to mitigate XSS risks.
Key Concerns
- Unprotected AJAX handler found
- No output escaping implemented
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
SF Generate Tags Security Vulnerabilities
SF Generate Tags Code Analysis
Output Escaping
SF Generate Tags Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
SF Generate Tags Maintenance & Trust
Maintenance Signals
Community Trust
SF Generate Tags Alternatives
ThumbPress – Image Management Suite for Performance and Optimization
image-sizes
Disable Thumbnails, Regenerate Thumbnails, Compress Images, Convert to WebP, Find Unused and Large Images, Edit Images, and more with ThumbPress.
Empty Tags Remover
empty-tags-remover
Really simple plugin. It just removes all your empty tags on demand.
Tag Generator
tag-generator
Generates tags for posts, using Yahoo and Yandex API.
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
SF Generate Tags Developer Profile
3 plugins · 50 total installs
How We Detect SF Generate Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sf-generate-tags/sf-tags-admin.php/wp-content/plugins/sf-generate-tags/sf-tags-filter-english.phpHTML / DOM Fingerprints
sf-generate-tags-formid="sf_from_images"id="sf_from_text"id="sf_post_id"id="sf_limit_tags"id="btnSubmit"id="sf_remove_words"+1 morewindow.ajaxurlwp-json/sf-generate-tags