
Tally Homepage Control Security & Risk Analysis
wordpress.org/plugins/tally-homepage-controlCustomize or Edit Home page Content for Tally Themes
Is Tally Homepage Control Safe to Use in 2026?
Generally Safe
Score 85/100Tally Homepage Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Tally Homepage Control plugin version 1.6 presents a moderate security risk primarily due to its handling of its single AJAX entry point. While the plugin has no recorded vulnerability history and appears to have a clean record, the static analysis reveals significant security concerns within its codebase. The presence of an AJAX handler without any authentication checks is a major red flag, potentially allowing any unauthenticated user to trigger actions within the plugin. This, combined with the use of the `unserialize` function and a high percentage of SQL queries not utilizing prepared statements, significantly increases the attack surface and the likelihood of code injection or data manipulation vulnerabilities. Although the taint analysis did not identify critical or high severity flows, the underlying patterns of insecure coding practices warrant caution. The plugin shows a strength in its complete output escaping and lack of file operations or external HTTP requests, but these are overshadowed by the critical flaws in its input validation and data handling.
Key Concerns
- AJAX handler without auth checks
- Unserialize function used
- SQL queries without prepared statements
- Low output escaping percentage
- No capability checks
Tally Homepage Control Security Vulnerabilities
Tally Homepage Control Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Tally Homepage Control Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Tally Homepage Control Maintenance & Trust
Maintenance Signals
Community Trust
Tally Homepage Control Alternatives
WooBuilder
woobuilder
WooBuilder lets you take complete control of your product layout, let's you create advanced, professional looking product page layouts.
Booster Pack for Divi
booster-pack-for-divi
Adds many more useful widgets to Divi Page Builder
WP Munich Blocks – Gutenberg Blocks for WordPress
wp-munich-blocks
Create amazing content with the new WordPress block editor and the WP Munich blocks.
Booster Pack for Beaver Builder
booster-beaver
Booster Pack for Beaver Builder is a collection new and exciting widgets to Beaver Builder Plugin.
Page Builder Companion
page-builder-companion
Page Builder Companion helps you build fascinating full width pages with three different template types. Choose the one you like and enjoy displaying …
Tally Homepage Control Developer Profile
5 plugins · 130 total installs
How We Detect Tally Homepage Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tally-homepage-control/assets/bootstrap/css/bootstrap.min.css/wp-content/plugins/tally-homepage-control/assets/css/animate.css/wp-content/plugins/tally-homepage-control/assets/css/tallybuilder.css/wp-content/plugins/tally-homepage-control/assets/css/tallybuilder-admin.css/wp-content/plugins/tally-homepage-control/assets/js/tallybuilder-admin.js/wp-content/plugins/tally-homepage-control/assets/bootstrap/js/bootstrap.min.js/wp-content/plugins/tally-homepage-control/assets/js/wow.min.js/wp-content/plugins/tally-homepage-control/assets/js/tallybuilder.js/wp-content/plugins/tally-homepage-control/assets/js/tallybuilder-admin.js/wp-content/plugins/tally-homepage-control/assets/js/tallybuilder.js/wp-content/plugins/tally-homepage-control/assets/bootstrap/js/bootstrap.min.js/wp-content/plugins/tally-homepage-control/assets/js/wow.min.jsHTML / DOM Fingerprints
tallybuilder-adminbootstrapanimatetallybuilderdata-tallybuilder-parent-page