Simple Taxonomy Refreshed Security & Risk Analysis

wordpress.org/plugins/simple-taxonomy-refreshed

This plugin provides a no-code facility to manage your taxonomies - either by defining your own or by adding additional function to existing ones.

500 active installs v3.3.1 PHP 7.4+ WP 4.9+ Updated Mar 6, 2026
categorycustom-taxonomiestagstaxonomiestaxonomy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Taxonomy Refreshed Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Taxonomy Refreshed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The overall security posture of "simple-taxonomy-refreshed" v3.3.1 appears to be strong, with several good security practices evident in the static analysis. All identified entry points (AJAX handlers and shortcodes) are accounted for, and importantly, none are reported as unprotected. The plugin demonstrates a commendable commitment to secure coding by exclusively using prepared statements for all SQL queries, significantly mitigating SQL injection risks. Furthermore, a high percentage of output escaping (86%) suggests a good effort to prevent Cross-Site Scripting (XSS) vulnerabilities. The presence of 14 nonce checks and 15 capability checks further reinforces the plugin's defensive measures against unauthorized actions.

Despite these strengths, there are minor areas for attention. The presence of one flow with an unsanitized path in the taint analysis, while not classified as critical or high, warrants investigation to understand the potential impact. Although the plugin has no recorded vulnerabilities (CVEs), this does not guarantee future immunity. A consistent history of zero vulnerabilities can sometimes be due to limited analysis or a lack of exploitation attempts, rather than inherent invulnerability. The file operations, while not detailed in terms of risk, are another area that might benefit from closer inspection to ensure secure handling.

In conclusion, "simple-taxonomy-refreshed" v3.3.1 exhibits robust security fundamentals, particularly in its handling of database interactions and access control. The absence of known vulnerabilities is a positive sign. However, the single unsanitized path identified in the taint analysis, along with the generally limited details on file operations, represents potential, albeit low-level, risks that could be addressed through further code review. Continued vigilance and regular security audits are always recommended for any plugin.

Key Concerns

  • Flows with unsanitized paths
  • Minor portion of outputs not properly escaped
Vulnerabilities
None known

Simple Taxonomy Refreshed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Taxonomy Refreshed Release Timeline

v3.3.1Current
v3.3.0
v3.2.0
v3.1.1
v3.1.0
v3.0.0
v2.3.0
v2.2.0
v2.1.0
v2.0.0
v1.3.0
v1.2.2
v1.2.1
v1.2.0
v1.1.1
v1.1.0
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Simple Taxonomy Refreshed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
18 prepared
Unescaped Output
85
510 escaped
Nonce Checks
14
Capability Checks
15
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared18 total queries

Output Escaping

86% escaped595 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

13 flows1 with unsanitized paths
page_importation (includes\class-simpletaxonomyrefreshed-admin-import.php:185)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Taxonomy Refreshed Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_staxo_convertincludes\class-simpletaxonomyrefreshed-admin-conversion.php:48
authwp_ajax_staxo_mergeincludes\class-simpletaxonomyrefreshed-admin-merge.php:48

Shortcodes 1

[staxo_post_terms] includes\class-simpletaxonomyrefreshed-client.php:64
WordPress Hooks 42
actionadmin_initincludes\class-simpletaxonomyrefreshed-admin-config.php:48
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-config.php:49
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-conversion.php:46
actionadmin_initincludes\class-simpletaxonomyrefreshed-admin-import.php:46
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-import.php:47
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-merge.php:46
actionadmin_initincludes\class-simpletaxonomyrefreshed-admin-order.php:46
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-order.php:47
actionadmin_initincludes\class-simpletaxonomyrefreshed-admin-rename.php:46
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin-rename.php:47
actionactivity_box_endincludes\class-simpletaxonomyrefreshed-admin.php:174
actionadmin_initincludes\class-simpletaxonomyrefreshed-admin.php:175
actionadmin_menuincludes\class-simpletaxonomyrefreshed-admin.php:176
actionadmin_enqueue_scriptsincludes\class-simpletaxonomyrefreshed-admin.php:179
actionall_admin_noticesincludes\class-simpletaxonomyrefreshed-admin.php:182
actionenqueue_block_editor_assetsincludes\class-simpletaxonomyrefreshed-admin.php:185
filterwp_insert_post_empty_contentincludes\class-simpletaxonomyrefreshed-admin.php:256
actionadmin_noticesincludes\class-simpletaxonomyrefreshed-admin.php:259
actionrest_api_initincludes\class-simpletaxonomyrefreshed-client.php:55
actionrest_api_initincludes\class-simpletaxonomyrefreshed-client.php:56
actioninitincludes\class-simpletaxonomyrefreshed-client.php:57
actioninitincludes\class-simpletaxonomyrefreshed-client.php:58
actioninitincludes\class-simpletaxonomyrefreshed-client.php:59
actionadmin_initincludes\class-simpletaxonomyrefreshed-client.php:60
filterthe_excerptincludes\class-simpletaxonomyrefreshed-client.php:62
filterthe_contentincludes\class-simpletaxonomyrefreshed-client.php:63
filterthe_category_rssincludes\class-simpletaxonomyrefreshed-client.php:65
actiontemplate_redirectincludes\class-simpletaxonomyrefreshed-client.php:67
filterwp_titleincludes\class-simpletaxonomyrefreshed-client.php:68
actionrestrict_manage_postsincludes\class-simpletaxonomyrefreshed-client.php:70
actionregistered_taxonomyincludes\class-simpletaxonomyrefreshed-client.php:75
filterupdate_post_term_count_statusesincludes\class-simpletaxonomyrefreshed-client.php:171
filterqueryincludes\class-simpletaxonomyrefreshed-client.php:924
filterterms_clausesincludes\class-simpletaxonomyrefreshed-widget.php:170
filterwp_generate_tag_cloudincludes\class-simpletaxonomyrefreshed-widget.php:172
filterterms_clausesincludes\class-simpletaxonomyrefreshed-widget.php:199
actionplugins_loadedsimple-taxonomy-refreshed.php:42
actionwp_headsimple-taxonomy-refreshed.php:56
actionwidgets_initsimple-taxonomy-refreshed.php:70
actionwidgets_initsimple-taxonomy-refreshed.php:104
filterwidget_types_to_hide_from_legacy_widget_blocksimple-taxonomy-refreshed.php:107
actioninitsimple-taxonomy-refreshed.php:110
Maintenance & Trust

Simple Taxonomy Refreshed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.4
Downloads10K

Community Trust

Rating100/100
Number of ratings5
Active installs500
Developer Profile

Simple Taxonomy Refreshed Developer Profile

nwjames

2 plugins · 500 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Taxonomy Refreshed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-taxonomy-refreshed/js/placeholder.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.js/wp-content/plugins/simple-taxonomy-refreshed/css/staxo-admin-style.dev.css/wp-content/plugins/simple-taxonomy-refreshed/css/staxo-admin-style.css/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.js
Script Paths
/wp-content/plugins/simple-taxonomy-refreshed/js/placeholder.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-admin.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.dev.js/wp-content/plugins/simple-taxonomy-refreshed/js/staxo-client.js

HTML / DOM Fingerprints

CSS Classes
b-t
JS Globals
staxo_placeholderstaxo_adminstaxo_client
FAQ

Frequently Asked Questions about Simple Taxonomy Refreshed