
Tag list Security & Risk Analysis
wordpress.org/plugins/tag-listTag list plugin
Is Tag list Safe to Use in 2026?
Generally Safe
Score 85/100Tag list has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tag-list' v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers and REST API routes without proper authentication, coupled with a single shortcode as the only entry point, significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by using prepared statements for its single SQL query and includes a nonce check. The vulnerability history is clean, with no known CVEs, indicating a track record of security awareness or lack of discovered exploitable flaws.
However, a critical weakness is identified in output escaping, where 100% of outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as any data displayed to users, whether user-generated or otherwise, could be injected with malicious scripts. While other security signals are positive, this single unescaped output poses a substantial threat that overshadows the otherwise good practices. The lack of capability checks on the shortcode is also a concern, as it implies that any logged-in user might be able to trigger its functionality without explicit authorization.
In conclusion, 'tag-list' v1.1.1 has several strengths, particularly in its limited attack surface and use of prepared statements. The absence of historical vulnerabilities is a positive indicator. Nevertheless, the critical issue of unescaped output and the potential for unauthorized shortcode execution introduce significant security risks that require immediate attention.
Key Concerns
- 100% of outputs are not properly escaped
- Shortcode lacks capability checks
Tag list Security Vulnerabilities
Tag list Release Timeline
Tag list Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tag list Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Tag list Maintenance & Trust
Maintenance Signals
Community Trust
Tag list Alternatives
Connect Polylang for Elementor
connect-polylang-elementor
Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Enhanced Media Library
enhanced-media-library
This plugin would be handy for those who need to manage a lot of media files.
Media Library Assistant
media-library-assistant
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
Tag list Developer Profile
23 plugins · 89K total installs
How We Detect Tag list
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-list/default.cssHTML / DOM Fingerprints
tag-toctag-list init() get_options() get_iworks_tag_list() get_css()+1 moreid="tag-list"id="tag-toc"href="#tag-id="tag-href="%s"<div id="tag-list"><ul class="tag-toc"><li id="tag-<h4>