
Sk Multi Tag Security & Risk Analysis
wordpress.org/plugins/sk-multi-tagThis plugin adds a tag cloud widget where you can select multiple tags at once.
Is Sk Multi Tag Safe to Use in 2026?
Generally Safe
Score 85/100Sk Multi Tag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sk-multi-tag' v1.0.2 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and its static analysis shows no critical or high severity taint flows, suggesting a lack of readily exploitable pathways for common attacks. Additionally, all SQL queries utilize prepared statements, which is a strong defense against SQL injection. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, there are significant concerns regarding code quality and best practices. The presence of the deprecated `create_function` in three instances is a red flag, as this function can be a source of security vulnerabilities if not used with extreme care, and it's generally advised to avoid it in modern PHP development. Furthermore, only 26% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks across all entry points is another critical oversight, especially if any of the AJAX handlers or REST API routes were to be added in the future, as this would leave them unprotected.
The plugin's vulnerability history of zero recorded CVEs is a positive indicator, but it could also be a reflection of the plugin's limited adoption or the thoroughness of past security audits. The outdated bundled jQuery library (v1.4.2) presents a known risk, as older versions often contain exploitable vulnerabilities. In conclusion, while the plugin currently lacks known external vulnerabilities and employs secure SQL practices, the internal code quality issues, particularly unescaped output and the use of `create_function`, alongside the outdated library, present significant potential risks that require remediation.
Key Concerns
- High percentage of unescaped output
- Use of deprecated create_function
- Bundled outdated jQuery library
- No nonce checks on entry points
- No capability checks on entry points
Sk Multi Tag Security Vulnerabilities
Sk Multi Tag Release Timeline
Sk Multi Tag Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Sk Multi Tag Attack Surface
WordPress Hooks 3
Maintenance & Trust
Sk Multi Tag Maintenance & Trust
Maintenance Signals
Community Trust
Sk Multi Tag Alternatives
Most Popular Tags
most-popular-tags
Most Popular Tags is a plugin that displays your WordPress site's most popular tags, categories and custom taxonomies as a sidebar widget.
Minimalist Tag Cloud
minimalist-tag-cloud
Customisable widget and shortcode to display tag cloud with option to show tag count anywhere you want.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Social Feed Gallery
insta-gallery
Formerly known as "Instagram Feed", this is the best plugin for displaying Instagram feeds on WordPress. It also supports Instagram reels.
Sk Multi Tag Developer Profile
2 plugins · 20 total installs
How We Detect Sk Multi Tag
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sk-multi-tag/widget.php/wp-content/plugins/sk-multi-tag/module.phpsk-multi-tag/style.css?ver=sk-multi-tag/admin.css?ver=sk-multi-tag/sk-mt-public.js?ver=sk-multi-tag/sk-mt-admin.js?ver=HTML / DOM Fingerprints
sk_multitag_cloudskmt-admin<!-- Here you can create a new tag cloud style --><!-- Info -->data-skmt-iddata-skmt-widget-idskMultiTagAdmin[sk_multitag_cloud][sk_multitag_cloud id="some-id"]