
Tags to Keywords Security & Risk Analysis
wordpress.org/plugins/tags-to-meta-keywordsAdd tags in head of page as meta's keywords
Is Tags to Keywords Safe to Use in 2026?
Generally Safe
Score 99/100Tags to Keywords has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "tags-to-meta-keywords" v1.0.4 exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, as is the complete avoidance of dangerous functions and file operations. Furthermore, the plugin demonstrates best practices by using prepared statements for all SQL queries and ensuring all output is properly escaped. The presence of a nonce check is also a positive indicator of security awareness.
However, the vulnerability history presents a notable concern. While there are no currently unpatched vulnerabilities, the plugin has a history of known CVEs, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability reported as recently as January 31, 2025. This suggests that while the developers may be addressing vulnerabilities, the potential for them to arise exists. The static analysis showed no critical or high severity taint flows, but the absence of capability checks on any entry points, combined with the historical CSRF issue, means that authentication and authorization are not explicitly verified for potential, albeit currently unexposed, functionality.
In conclusion, the plugin's codebase appears to be written with security in mind, utilizing prepared statements and output escaping effectively. The limited attack surface is also commendable. Nevertheless, the recurring vulnerability history, even if patched, warrants caution. The lack of explicit capability checks, while not an issue in the current analysis due to the zero attack surface, could become a risk if functionality were to be added in the future without proper authorization controls.
Key Concerns
- Medium severity CVE in history
- No capability checks on entry points
Tags to Keywords Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tags to Keywords <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-site Scripting
Tags to Keywords Code Analysis
Output Escaping
Data Flow Analysis
Tags to Keywords Attack Surface
WordPress Hooks 3
Maintenance & Trust
Tags to Keywords Maintenance & Trust
Maintenance Signals
Community Trust
Tags to Keywords Alternatives
Basic SEO Pack
basic-seo-pack
Simple but complete SEO Pack to make your site SEO Friendly. Quick way to add meta tags to your post and pages using WP custom fields.
Simple Meta Tags
simple-meta-tags
Allows you to set global meta tags and customize on each individual page/post. Please Note: Does not support custom post types
Meta Keywords for Each Page
meta-keywords-for-each-page
Easily add SEO meta keywords to enhance your website's search engine optimization.
Simple SEO Pack
simple-seo-pack
Simple SEO is a quick way to add HTML meta tags to your site and pages using WP integrated custom fields feature.
Dynamic URL SEO
dynamic-url-seo
This plugin is used to add meta title, keywords and description for dynamic URLs which are not available in database.
Tags to Keywords Developer Profile
2 plugins · 400 total installs
How We Detect Tags to Keywords
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrap