
Tag Generator Security & Risk Analysis
wordpress.org/plugins/tag-generatorGenerates tags for posts, using Yahoo and Yandex API.
Is Tag Generator Safe to Use in 2026?
Generally Safe
Score 85/100Tag Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tag-generator" plugin v0.1.3.7 presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with zero identified entry points requiring authentication or permission checks. Furthermore, there are no recorded past vulnerabilities, suggesting a history of stable and potentially secure development.
However, significant concerns arise from the static code analysis. The complete absence of prepared statements for all four SQL queries is a major risk, leaving the plugin highly susceptible to SQL injection attacks. Compounding this, a very low percentage (6%) of output is properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis further highlights this, with all five analyzed flows having unsanitized paths and three of them flagged as high severity. The plugin also performs external HTTP requests, which, without proper validation, could lead to SSRF vulnerabilities or unintended data leakage.
In conclusion, while the lack of a public vulnerability history and a minimal attack surface are strengths, the critical flaws in handling SQL queries and output escaping, as evidenced by the taint analysis, represent immediate and severe security risks that require urgent attention. The absence of nonces and capability checks, while not directly exploited due to the zero attack surface, would be major concerns if any entry points were present.
Key Concerns
- All SQL queries use raw SQL, not prepared statements
- Very low percentage of output is properly escaped
- High severity taint flows with unsanitized paths
- No nonce checks implemented
- No capability checks implemented
- External HTTP requests present
Tag Generator Security Vulnerabilities
Tag Generator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tag Generator Attack Surface
WordPress Hooks 2
Maintenance & Trust
Tag Generator Maintenance & Trust
Maintenance Signals
Community Trust
Tag Generator Alternatives
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
Automatic Post Tagger
automatic-post-tagger
Adds relevant taxonomy terms to posts using a keyword list provided by the user.
Tag Generator Developer Profile
1 plugin · 20 total installs
How We Detect Tag Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-generator/style.css/wp-content/plugins/tag-generator/admin.css/wp-content/plugins/tag-generator/taggenerator.jstag-generator/style.css?ver=tag-generator/admin.css?ver=tag-generator/taggenerator.js?ver=HTML / DOM Fingerprints
taggenerator_admintaggenerator