
Tainacan Extra View Modes Security & Risk Analysis
wordpress.org/plugins/tainacan-extra-view-modesA view modes plugin for Tainacan, which registers a list of 8 extra view modes that may be used to display your items list.
Is Tainacan Extra View Modes Safe to Use in 2026?
Generally Safe
Score 100/100Tainacan Extra View Modes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Tainacan Extra View Modes plugin, version 0.0.6, exhibits a mixed security posture. While the plugin demonstrates good practices by avoiding dangerous functions, raw SQL queries, and external HTTP requests, significant concerns arise from its attack surface and input handling. The presence of an unprotected AJAX handler presents a clear entry point for potential attacks without any form of authentication or authorization checks. Furthermore, a substantial portion of output escaping is missing (62% properly escaped), indicating a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly in the output.
The vulnerability history for this plugin is clean, with no known CVEs recorded. This is a positive indicator, suggesting that the developers have either had a good track record or the plugin has not been subjected to extensive public scrutiny or targeted attacks. However, the lack of historical vulnerabilities should not overshadow the immediate risks identified in the static analysis. The limited code analysis depth, with zero total flows analyzed in the taint analysis, also means that potentially more complex vulnerabilities might have been missed.
In conclusion, the plugin's strengths lie in its avoidance of common risky practices like raw SQL and external requests. However, the critical weakness of an unprotected AJAX handler and insufficient output escaping pose immediate and significant security risks. The absence of historical vulnerabilities is encouraging but does not mitigate the current code-level concerns. Recommendations should focus on addressing the unprotected AJAX endpoint and improving output sanitization.
Key Concerns
- Unprotected AJAX handler
- Insufficient output escaping
- No nonce checks on AJAX
Tainacan Extra View Modes Security Vulnerabilities
Tainacan Extra View Modes Code Analysis
Output Escaping
Tainacan Extra View Modes Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Tainacan Extra View Modes Maintenance & Trust
Maintenance Signals
Community Trust
Tainacan Extra View Modes Alternatives
Tainacan
tainacan
A powerful and flexible open-source repository platform that brings digital collection management to WordPress.
Tainacan Support for Blocksy
tainacan-blocksy
A plugin for integrating Tainacan plugin pages with the amazing Blocksy theme.
Tainacan URL Metadata Type
tainacan-url-metadata-type
This plugin is not required anymore if you are using Tainacan 0.21.0, as the URL metadata type has become an official metadata type inside the plugin.
Disable Author Archives
disable-author-archives
Disable Author Archives completely removes author archives and makes the web server return status code 404 ('Not Found') instead.
Simple Yearly Archive
simple-yearly-archive
Simple Yearly Archive is a rather neat and simple Wordpress plugin that allows you to display your archives in a year-based list.
Tainacan Extra View Modes Developer Profile
6 plugins · 3K total installs
How We Detect Tainacan Extra View Modes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-albums.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-books.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-document.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-exhibition.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-frame.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-mosaic.php/wp-content/plugins/tainacan-extra-view-modes/templates/view-mode-polaroid.php/wp-content/plugins/tainacan-extra-view-modes/style.css?ver=HTML / DOM Fingerprints
view-mode-mosaic-legacyview-mode-frameview-mode-exhibitionview-mode-booksview-mode-polaroidview-mode-documentview-mode-albumsdata-tainacan-view-mode