Simple Tags Importer Security & Risk Analysis

wordpress.org/plugins/stp-importer

Import Simple Tagging tags into WordPress tags.

30 active installs v0.3.1 PHP + WP 3.0+ Updated Dec 6, 2022
importersimple-tagging
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Tags Importer Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Tags Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "stp-importer" plugin v0.3.1 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities, uses prepared statements for its single SQL query, and has no file operations or external HTTP requests, which are excellent signs. The presence of nonce checks and a lack of critical taint analysis findings suggest a conscious effort towards security. However, a significant concern arises from the complete lack of output escaping on all 17 identified outputs. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data that is manipulated by user input could be directly rendered in the browser without sanitization.

The vulnerability history being completely clear is a strong indicator of good development practices historically. The absence of any CVEs suggests the plugin has either been very well-maintained or has not been a significant target. However, this does not negate the immediate risks identified in the static analysis. The plugin's attack surface is currently zero, which is excellent, but this could change with future updates. The lack of capability checks on the entry points (if they existed) would be a concern, but as it stands, the primary weakness is the unescaped output.

In conclusion, while the plugin has a clean history and good practices in some areas like database interaction and external communication, the unescaped output is a critical flaw that needs immediate attention. The plugin's security is severely undermined by this oversight, making it vulnerable to XSS attacks. The lack of documented vulnerabilities is a positive, but the static analysis highlights a clear and present danger that outweighs this historical data.

Key Concerns

  • Unescaped output on all outputs
Vulnerabilities
None known

Simple Tags Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Tags Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
0 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped17 total outputs
Attack Surface

Simple Tags Importer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitstp-importer.php:192
Maintenance & Trust

Simple Tags Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedDec 6, 2022
PHP min version
Downloads12K

Community Trust

Rating40/100
Number of ratings4
Active installs30
Developer Profile

Simple Tags Importer Developer Profile

briancolinger

11 plugins · 113K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Tags Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
Shortcode Output
<h2>Import Simple Tagging</h2><p>Steps may take a few minutes depending on the size of your database. Please be patient.</p><br /><br /></p><p>Howdy! This imports tags from Simple Tagging 1.6.2 into WordPress tags.</p><p>This has not been tested on any other versions of Simple Tagging. Mileage may vary.</p>
FAQ

Frequently Asked Questions about Simple Tags Importer