
Tag Display Security & Risk Analysis
wordpress.org/plugins/tag-displayTag Display is a WordPress plugin to display post tags with multiple templates, custom colors, and full control over output.
Is Tag Display Safe to Use in 2026?
Generally Safe
Score 100/100Tag Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tag-display" v1.7.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are positive indicators. Furthermore, the high percentage of properly escaped output (91%) suggests good practices in preventing cross-site scripting (XSS) vulnerabilities.
However, there are a few areas that warrant attention. The plugin does not implement any nonce checks or capability checks. While the attack surface appears small with only one shortcode and no unprotected entry points, the lack of these security mechanisms means that the shortcode's functionality, if it were to process any user-supplied data, could potentially be exploited without proper authentication or authorization. The taint analysis yielded no critical or high severity flows, which is reassuring, but the fact that zero flows were analyzed limits the scope of this assessment. The vulnerability history being entirely clear is a significant strength, indicating a track record of security diligence.
In conclusion, "tag-display" v1.7.0 is well-developed from a security perspective, particularly in its handling of data and code execution. The main concern lies in the absence of nonce and capability checks, which, while not exploited in the current analysis, represent a potential weakness that could be exploited if the shortcode's functionality were to evolve to handle user input. The plugin's clean vulnerability history is a strong positive.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Taint analysis not fully performed
Tag Display Security Vulnerabilities
Tag Display Code Analysis
Output Escaping
Tag Display Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Tag Display Maintenance & Trust
Maintenance Signals
Community Trust
Tag Display Alternatives
Tag Cloud Shortcode
tag-cloud-shortcode
The plugin enables any page or post author to include a Tag Cloud by using a shortcode instead of hacking theme template files.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Ultimate Tag Cloud Widget
ultimate-tag-cloud-widget
This plugin aims to be the most configurable tag cloud widget out there, able to suit all your weird tag cloud needs.
Tag Groups is the Advanced Way to Display Your Taxonomy Terms
tag-groups
Tag Groups allows you to organize your WordPress taxonomy terms and show them in clouds, tabs, accordions, tables, lists and much more.
Configurable Tag Cloud (CTC)
configurable-tag-cloud-widget
Display a tag cloud customized with your preferences in the sidebar.
Tag Display Developer Profile
1 plugin · 10 total installs
How We Detect Tag Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-display/admin/css/tag-display-admin.css/wp-content/plugins/tag-display/admin/js/tag-display-admin.jstag-display/admin/css/tag-display-admin.css?ver=tag-display/admin/js/tag-display-admin.js?ver=