Tags to Keywords Security & Risk Analysis

wordpress.org/plugins/tags-to-meta-keywords

Add tags in head of page as meta's keywords

300 active installs v1.0.4 PHP + WP 2.3+ Updated Nov 28, 2025
headkeywordsmetaseotags
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2025
Safety Verdict

Is Tags to Keywords Safe to Use in 2026?

Generally Safe

Score 99/100

Tags to Keywords has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 31, 2025Updated 4mo ago
Risk Assessment

The plugin "tags-to-meta-keywords" v1.0.4 exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, as is the complete avoidance of dangerous functions and file operations. Furthermore, the plugin demonstrates best practices by using prepared statements for all SQL queries and ensuring all output is properly escaped. The presence of a nonce check is also a positive indicator of security awareness.

However, the vulnerability history presents a notable concern. While there are no currently unpatched vulnerabilities, the plugin has a history of known CVEs, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability reported as recently as January 31, 2025. This suggests that while the developers may be addressing vulnerabilities, the potential for them to arise exists. The static analysis showed no critical or high severity taint flows, but the absence of capability checks on any entry points, combined with the historical CSRF issue, means that authentication and authorization are not explicitly verified for potential, albeit currently unexposed, functionality.

In conclusion, the plugin's codebase appears to be written with security in mind, utilizing prepared statements and output escaping effectively. The limited attack surface is also commendable. Nevertheless, the recurring vulnerability history, even if patched, warrants caution. The lack of explicit capability checks, while not an issue in the current analysis due to the zero attack surface, could become a risk if functionality were to be added in the future without proper authorization controls.

Key Concerns

  • Medium severity CVE in history
  • No capability checks on entry points
Vulnerabilities
1

Tags to Keywords Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22685medium · 6.1Cross-Site Request Forgery (CSRF)

Tags to Keywords <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-site Scripting

Jan 31, 2025 Patched in 1.0.2 (4d)
Code Analysis
Analyzed Mar 16, 2026

Tags to Keywords Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ttk_save_options (tags-to-keywords.php:52)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tags to Keywords Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headtags-to-keywords.php:27
actionadmin_menutags-to-keywords.php:29
actionadmin_inittags-to-keywords.php:30
Maintenance & Trust

Tags to Keywords Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Tags to Keywords Developer Profile

CheGevara29

2 plugins · 400 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect Tags to Keywords

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Tags to Keywords