
Tag This Security & Risk Analysis
wordpress.org/plugins/tag-this"Tag This" is a wordpress plugin that allows the community to appropriately tag your posts. It does so by adding a small textbox below a pos …
Is Tag This Safe to Use in 2026?
Generally Safe
Score 85/100Tag This has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tag-this" plugin v0.9.0 exhibits a mixed security posture. While it demonstrates strong practices in SQL query handling with 100% prepared statements and no known CVEs, significant concerns arise from its code analysis.
The plugin utilizes dangerous functions like `popen` and `exec`, which are inherently risky and can lead to arbitrary code execution if not handled with extreme care. Furthermore, the taint analysis reveals three flows with unsanitized paths, indicating potential for path traversal vulnerabilities. The absence of nonce checks and capability checks on its identified entry points (though limited in number) is a major security gap, leaving any potential functionalities exposed to unauthorized access and manipulation.
In conclusion, despite a clean vulnerability history and secure SQL practices, the presence of dangerous functions, unsanitized paths in taint flows, and a complete lack of authorization checks on entry points present a considerable risk. The plugin's strengths in database interaction are overshadowed by critical weaknesses in input validation and function execution security.
Key Concerns
- Dangerous functions used (popen, exec)
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
- Low percentage of properly escaped output
Tag This Security Vulnerabilities
Tag This Release Timeline
Tag This Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Tag This Attack Surface
WordPress Hooks 4
Maintenance & Trust
Tag This Maintenance & Trust
Maintenance Signals
Community Trust
Tag This Alternatives
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Regenerate Thumbnails
regenerate-thumbnails
Regenerate the thumbnails for one or more of your image uploads. Useful when changing their sizes or your theme.
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Tag This Developer Profile
2 plugins · 20 total installs
How We Detect Tag This
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tagthis/tagthis-js.php/wp-content/plugins/tagthis/tagthistemp.jsHTML / DOM Fingerprints
tt-helptt-finished<!-- Start Of Script Generated By Tagthis --><!-- End Of Script Generated By Tagthis -->id="tagthisid="tagtextid="tt-helpid="tt-finishedonclick="ajaxAddTag(onclick="toggle(+2 more<div id="tagthis<input type="text" name="tag" id="tagtext<input type="button" onclick="ajaxAddTag(<a onclick="toggle(