
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Security & Risk Analysis
wordpress.org/plugins/simple-tagsTags, Categories and WordPress terms are easy with TaxoPress. Add a Tag or Category to Pages, manage your WooCommerce Categories and Tags and more.
Is Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Safe to Use in 2026?
Generally Safe
Score 95/100Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "simple-tags" v3.44.0 plugin exhibits a mixed security posture. On the positive side, the code analysis shows a significant percentage of SQL queries utilizing prepared statements, a high number of nonce and capability checks, and no identified critical or high severity taint flows, indicating good development practices in some areas. The absence of unpatched CVEs is also a strength.
However, there are notable concerns. A substantial portion of the plugin's attack surface, specifically 13 out of 33 entry points (AJAX handlers), lack proper authentication checks. This leaves these handlers vulnerable to unauthorized access and potential exploitation. Furthermore, while overall output escaping is decent, the presence of 40 flows with unsanitized paths, even if not classified as critical or high severity in this analysis, represents a potential risk for cross-site scripting or other input-related vulnerabilities if the data is not handled carefully later in the execution chain. The plugin's vulnerability history, with 13 medium severity CVEs primarily related to missing authorization, SQL injection, information exposure, and XSS, suggests a recurring pattern of vulnerabilities that attackers could potentially exploit if these issues are not thoroughly addressed and prevented in future development.
In conclusion, while the plugin has strengths in its use of prepared statements and checks, the significant number of unprotected AJAX endpoints and the historical pattern of medium severity vulnerabilities point to areas requiring immediate attention to improve its overall security. The unsanitized path flows also warrant careful monitoring and remediation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Large attack surface without auth checks
- 13 medium severity CVEs in history
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
TaxoPress <= 3.44.0 - Authenticated (Editor+) SQL Injection
TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.0 - Authenticated (Editor+) SQL Injection
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.37.2 - Authenticated (Subscriber+) Information Exposure
WordPress Tag, Category, and Taxonomy Manager – AI Autotagger <= 3.32.0 - Authenticated (Admin+) Stored Cross-Site Scripting
WordPress Tag and Category Manager – AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting
TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting
TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting
TaxoPress <= 3.4.4 - Reflected Cross-Site Scripting
TaxoPress <= 3.0.7.1 - Stored Cross-Site Scripting
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Release Timeline
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Attack Surface
AJAX Handlers 30
Shortcodes 3
WordPress Hooks 236
Scheduled Events 3
Maintenance & Trust
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Maintenance & Trust
Maintenance Signals
Community Trust
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Alternatives
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Ultimate Tag Cloud Elementor Addon
ultimate-tag-cloud
Ultimate Tag Cloud enhances tag display with dynamic loading, Elementor integration, and stylish layouts for better taxonomy organization.
Category Search Explorer
category-search-explorer
A powerful and user-friendly category search tool for WordPress. Perfect for sites with extensive categories, tags, or custom taxonomies.
Category View Row Action
category-view-row-action
Category View Row Action is a simple plugin which adds a 'View' link for your Categories and Tags in the admin section so that you can quick …
Dreamy Tags
dreamy-tags
Dreamy Tags displays a customizable tag cloud filtered by categories and tags for clean, meaningful blog and archive navigation.
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms Developer Profile
2 plugins · 53K total installs
How We Detect Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-tags/blocks/src/related-posts.js/wp-content/plugins/simple-tags/assets/frontend/css/frontend.css/wp-content/plugins/simple-tags/inc/loads.php/wp-content/plugins/simple-tags/blocks/src/related-posts.jssimple-tags/assets/frontend/css/frontend.css?ver=simple-tags/blocks/src/related-posts.js?ver=HTML / DOM Fingerprints
data-relatedpost_iddata-post_idST_RELATED_POST[taxopress_relatedposts id=