
Simple Taxonomy Refreshed Security & Risk Analysis
wordpress.org/plugins/simple-taxonomy-refreshedThis plugin provides a no-code facility to manage your taxonomies - either by defining your own or by adding additional function to existing ones.
Is Simple Taxonomy Refreshed Safe to Use in 2026?
Generally Safe
Score 100/100Simple Taxonomy Refreshed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of "simple-taxonomy-refreshed" v3.3.1 appears to be strong, with several good security practices evident in the static analysis. All identified entry points (AJAX handlers and shortcodes) are accounted for, and importantly, none are reported as unprotected. The plugin demonstrates a commendable commitment to secure coding by exclusively using prepared statements for all SQL queries, significantly mitigating SQL injection risks. Furthermore, a high percentage of output escaping (86%) suggests a good effort to prevent Cross-Site Scripting (XSS) vulnerabilities. The presence of 14 nonce checks and 15 capability checks further reinforces the plugin's defensive measures against unauthorized actions.
Despite these strengths, there are minor areas for attention. The presence of one flow with an unsanitized path in the taint analysis, while not classified as critical or high, warrants investigation to understand the potential impact. Although the plugin has no recorded vulnerabilities (CVEs), this does not guarantee future immunity. A consistent history of zero vulnerabilities can sometimes be due to limited analysis or a lack of exploitation attempts, rather than inherent invulnerability. The file operations, while not detailed in terms of risk, are another area that might benefit from closer inspection to ensure secure handling.
In conclusion, "simple-taxonomy-refreshed" v3.3.1 exhibits robust security fundamentals, particularly in its handling of database interactions and access control. The absence of known vulnerabilities is a positive sign. However, the single unsanitized path identified in the taint analysis, along with the generally limited details on file operations, represents potential, albeit low-level, risks that could be addressed through further code review. Continued vigilance and regular security audits are always recommended for any plugin.
Key Concerns
- Flows with unsanitized paths
- Minor portion of outputs not properly escaped
Simple Taxonomy Refreshed Security Vulnerabilities
Simple Taxonomy Refreshed Release Timeline
Simple Taxonomy Refreshed Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Taxonomy Refreshed Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 42
Maintenance & Trust
Simple Taxonomy Refreshed Maintenance & Trust
Maintenance Signals
Community Trust
Simple Taxonomy Refreshed Alternatives
Require Post Category
require-post-category
Require users to choose a post category before updating or publishing a post.
TagPages
tagpages
Adds post-tags functionality for pages.
Term Taxonomy Converter
term-taxonomy-converter
Copy or convert terms between taxonomies.
Taxonomy Checklist Tree
taxonomy-checklist-tree
Plugin sets Category/Taxonomy checklist hierarchical tree-view by default.
Category Description Widget
category-description-widget
Enables a widget with the category description.
Simple Taxonomy Refreshed Developer Profile
2 plugins · 500 total installs
How We Detect Simple Taxonomy Refreshed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-taxonomy-refreshed/js/placeholder.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.js/wp-content/plugins/simple-taxonomy-refreshed/css/staxo-admin-style.dev.css/wp-content/plugins/simple-taxonomy-refreshed/css/staxo-admin-style.css/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.js/wp-content/plugins/simple-taxonomy-refreshed/js/placeholder.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.jsHTML / DOM Fingerprints
b-tstaxo_placeholderstaxo_adminstaxo_client