Tag Cloud per Category Security & Risk Analysis

wordpress.org/plugins/tag-cloud-per-category

This is an override of the native Tag cloud widget but filtered by the current category.

50 active installs v1.0.0 PHP + WP 3.0+ Updated Jan 8, 2017
catcategoriestag-cloudtagswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tag Cloud per Category Safe to Use in 2026?

Generally Safe

Score 85/100

Tag Cloud per Category has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'tag-cloud-per-category' plugin, version 1.0.0, exhibits a generally positive security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests are strong indicators of secure coding practices.

However, the analysis does reveal a critical concern: 100% of SQL queries are not using prepared statements. This presents a significant risk of SQL injection vulnerabilities. Additionally, while there are multiple output operations, a substantial portion (60%) are not properly escaped, leading to potential cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a consistently secure development approach in the past. Despite the concerning SQL and output escaping issues, the minimal attack surface and absence of other common security flaws contribute to an overall moderate risk profile.

Key Concerns

  • 100% of SQL queries use raw SQL
  • 60% of output is not properly escaped
Vulnerabilities
None known

Tag Cloud per Category Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tag Cloud per Category Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Tag Cloud per Category Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
6
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

40% escaped10 total outputs
Attack Surface

Tag Cloud per Category Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_inittag-cloud-per-category.php:15
Maintenance & Trust

Tag Cloud per Category Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedJan 8, 2017
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs50
Developer Profile

Tag Cloud per Category Developer Profile

LordPretender

8 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tag Cloud per Category

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
tagcloud
FAQ

Frequently Asked Questions about Tag Cloud per Category