TagΒee Post Tagger Security & Risk Analysis

wordpress.org/plugins/tagbee-automatic-post-tagging

TagBee is the easy way to add tags to your posts.TagBee works in a simple way: it proposes tags for your content. However, under the hood, TagBee uses …

10 active installs v1.0.15 PHP + WP 3.7+ Updated May 30, 2025
auto-tagspostsseotaggingtags
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TagΒee Post Tagger Safe to Use in 2026?

Generally Safe

Score 100/100

TagΒee Post Tagger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The static analysis of the tagbee-automatic-post-tagging plugin v1.0.15 reveals a generally strong security posture. The plugin demonstrates excellent practices by having zero identified entry points without proper authentication checks, including AJAX handlers and REST API routes. Furthermore, the code signals indicate a complete absence of dangerous functions, raw SQL queries, and external HTTP requests. All identified output operations are properly escaped, and there are no file operations or bundled libraries, which eliminates common attack vectors. The presence of a capability check, even with a limited attack surface, is also a positive indicator.

While the plugin exhibits commendable security hygiene, the static analysis did not reveal any taint flows, making it difficult to assess risks related to data sanitation and manipulation. The complete absence of known vulnerabilities in its history is a significant strength, suggesting a history of secure development or a lack of past issues being publicly disclosed. However, the lack of identified entry points is unusual and could indicate either a very limited functionality or a potential oversight in the analysis scope itself. This, combined with the lack of taint analysis, means that while the plugin appears secure on the surface, deeper, dynamic analysis might be required to confirm the absence of subtle vulnerabilities that don't manifest as direct code signals.

In conclusion, based on the provided static analysis and vulnerability history, the tagbee-automatic-post-tagging plugin v1.0.15 presents a very low security risk. Its developers have adhered to many best practices, including secure handling of SQL queries and output. The lack of any known vulnerabilities is a significant positive. The primary area for potential improvement or further investigation would be to ensure that the analysis captured all potential interactions with the WordPress environment and that the absence of taint flows isn't due to a lack of complex data handling scenarios.

Vulnerabilities
None known

TagΒee Post Tagger Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TagΒee Post Tagger Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

TagΒee Post Tagger Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menutagbee-post-tagger.php:36
actionadmin_inittagbee-post-tagger.php:37
actionsave_posttagbee-post-tagger.php:38
actionadmin_noticestagbee-post-tagger.php:39
actionrest_after_insert_posttagbee-post-tagger.php:154
Maintenance & Trust

TagΒee Post Tagger Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 30, 2025
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

TagΒee Post Tagger Developer Profile

TagBee

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TagΒee Post Tagger

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TagΒee Post Tagger