
Casaca Security & Risk Analysis
wordpress.org/plugins/tainacan-reportsAdvanced reporting and analytics add-on for Tainacan digital collections platform.
Is Casaca Safe to Use in 2026?
Generally Safe
Score 100/100Casaca has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Tainacan Reports plugin v1.0.0 demonstrates a generally strong security posture in its static analysis. The complete absence of unprotected entry points, dangerous functions, raw SQL queries, and unescaped output are significant strengths. The presence of capability checks and nonce checks on all identified flows further indicates a good understanding of secure WordPress development practices. The plugin's vulnerability history is also clear, with no recorded CVEs, suggesting a potentially well-maintained codebase.
However, the taint analysis reveals a notable concern: all four analyzed flows have unsanitized paths. While the static analysis did not flag these as critical or high severity, unsanitized paths represent a potential risk, especially if they interact with file operations or external HTTP requests without proper sanitization. The presence of file operations (6) and external HTTP requests (3) alongside these unsanitized paths warrants careful attention. The use of bundled libraries (dompdf, TCPDF) also introduces a potential risk if these libraries are outdated and contain known vulnerabilities, though this is not directly evident from the provided data.
In conclusion, Tainacan Reports v1.0.0 exhibits good security practices in key areas like input validation and output escaping. The lack of known vulnerabilities is a positive sign. The primary area of concern lies in the unsanitized paths identified during taint analysis, which should be investigated further to ensure they do not lead to exploitable vulnerabilities, especially given the plugin's interaction with file operations and external requests.
Key Concerns
- Flows with unsanitized paths found
- Bundled libraries (dompdf, TCPDF)
Casaca Security Vulnerabilities
Casaca Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Casaca Attack Surface
WordPress Hooks 18
Scheduled Events 7
Maintenance & Trust
Casaca Maintenance & Trust
Maintenance Signals
Community Trust
Casaca Alternatives
Tainacan Support for Blocksy
tainacan-blocksy
A plugin for integrating Tainacan plugin pages with the amazing Blocksy theme.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
WP Client Reports
wp-client-reports
The best maintenance reporting tool for WordPress professionals. Display update statistics directly in the WordPress admin or send reports via email.
Tainacan
tainacan
A powerful and flexible open-source repository platform that brings digital collection management to WordPress.
REPORTiT – Advanced Reporting for WooCommerce
ithemelandco-woo-report
Stop guessing. Grow your sales with powerful, easy-to-understand reports and analytics for WooCommerce.
Casaca Developer Profile
6 plugins · 1K total installs
How We Detect Casaca
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tainacan-reports/dist/js/google-charts/loader.js/wp-content/plugins/tainacan-reports/dist/blocks/page/index.js/wp-content/plugins/tainacan-reports/dist/blocks/report/index.js/wp-content/plugins/tainacan-reports/dist/blocks/chart-bar/index.js/wp-content/plugins/tainacan-reports/dist/blocks/chart-table/index.js/wp-content/plugins/tainacan-reports/dist/blocks/chart-pie/index.js/wp-content/plugins/tainacan-reports/dist/blocks/image/index.js/wp-content/plugins/tainacan-reports/dist/app.css+1 moredist/js/google-charts/loader.jsdist/blocks/page/index.jsdist/blocks/report/index.jsdist/blocks/chart-bar/index.jsdist/blocks/chart-table/index.jsdist/blocks/chart-pie/index.js+3 moretainacan-reports/dist/js/google-charts/loader.js?ver=tainacan-reports/dist/blocks/page/index.js?ver=tainacan-reports/dist/blocks/report/index.js?ver=tainacan-reports/dist/blocks/chart-bar/index.js?ver=tainacan-reports/dist/blocks/chart-table/index.js?ver=tainacan-reports/dist/blocks/chart-pie/index.js?ver=tainacan-reports/dist/blocks/image/index.js?ver=tainacan-reports/dist/app.css?ver=tainacan-reports/dist/admin/post-types/reports/index.css?ver=HTML / DOM Fingerprints
tainacan-reports-generate-button<!-- tainacan_reports_generate_button --><!-- END tainacan_reports_generate_button -->data-tainacan-reports-generate-buttontainacanReportsNonces