
Tag Cloud Canvas Security & Risk Analysis
wordpress.org/plugins/tag-cloud-canvasThis widget add a tag cloud 3d to your sidebar.
Is Tag Cloud Canvas Safe to Use in 2026?
Generally Safe
Score 85/100Tag Cloud Canvas has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tag-cloud-canvas" plugin, version 0.1.0, presents a mixed security posture. On the positive side, the plugin exhibits excellent practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or CVEs. Furthermore, the attack surface appears minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. There are also no reported file operations or external HTTP requests, and no taint analysis reveals any critical or high severity issues.
However, several significant concerns are raised by the static code analysis. The presence of the `create_function` function is a serious red flag, as it can be a vector for code injection if used with unsanitized input. A shockingly low percentage of outputs are properly escaped (4%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any of the minimal attack surface points were to become exploitable. The complete absence of nonce and capability checks, even with a small attack surface, leaves any potential entry points vulnerable to unauthorized actions. The lack of taint analysis results, while potentially meaning no issues were found, could also be due to the limited analysis performed, not necessarily a guarantee of safety.
In conclusion, while the plugin benefits from a clean vulnerability history and secure database practices, the identified code quality issues, particularly the unescaped output and the use of `create_function`, represent substantial risks. The absence of security checks like nonces and capability checks further amplifies these concerns. Until these issues are addressed, the plugin should be considered moderately to highly risky.
Key Concerns
- High percentage of unescaped output
- Use of dangerous function 'create_function'
- No nonce checks present
- No capability checks present
Tag Cloud Canvas Security Vulnerabilities
Tag Cloud Canvas Code Analysis
Dangerous Functions Found
Output Escaping
Tag Cloud Canvas Attack Surface
WordPress Hooks 2
Maintenance & Trust
Tag Cloud Canvas Maintenance & Trust
Maintenance Signals
Community Trust
Tag Cloud Canvas Alternatives
Ultimate Tag Cloud Widget
ultimate-tag-cloud-widget
This plugin aims to be the most configurable tag cloud widget out there, able to suit all your weird tag cloud needs.
Configurable Tag Cloud (CTC)
configurable-tag-cloud-widget
Display a tag cloud customized with your preferences in the sidebar.
Most Popular Tags
most-popular-tags
Most Popular Tags is a plugin that displays your WordPress site's most popular tags, categories and custom taxonomies as a sidebar widget.
Random Tags Cloud Widget
random-tags-cloud-widget
Random Tags Cloud displays your tags by selecting randomly. Of course, you can customize other tag cloud's settings.
Muki Tag Cloud
muki-tag-cloud
Another wordpress tag cloud plugin based on jQCloud, which is creative, beauty and colorful.
Tag Cloud Canvas Developer Profile
1 plugin · 100 total installs
How We Detect Tag Cloud Canvas
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-cloud-canvas/css/tag-cloud-canvas.css/wp-content/plugins/tag-cloud-canvas/js/tag-cloud-canvas.js/wp-content/plugins/tag-cloud-canvas/js/tag-cloud-canvas.jstag-cloud-canvas/style.css?ver=tag-cloud-canvas/script.js?ver=HTML / DOM Fingerprints
id="tagCloudCanvasid="tags"tagcanvas<canvas id="tagCloudCanvas<div id="tags">