
Taxonomy Filter Security & Risk Analysis
wordpress.org/plugins/taxonomy-filterTaxonomy Filter is a plugin which allow users to filter hierarchical taxonomy terms inside admin pages and provides a way to hide terms for each user
Is Taxonomy Filter Safe to Use in 2026?
Generally Safe
Score 92/100Taxonomy Filter has a strong security track record. Known vulnerabilities have been patched promptly.
The "taxonomy-filter" plugin v2.2.13 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean slate regarding dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests. The presence of nonce and capability checks, though limited, also indicates some consideration for security. However, a significant concern arises from the complete lack of output escaping. With 47 total outputs and 0% properly escaped, this opens the door to potential Cross-Site Scripting (XSS) vulnerabilities where user-supplied data could be injected and executed in the browser.
The vulnerability history shows a past Medium severity Cross-Site Request Forgery (CSRF) vulnerability, which has since been patched. While there are no currently unpatched CVEs, the previous CSRF issue and the current lack of output escaping suggest a pattern where certain types of vulnerabilities might be overlooked during development or testing. The limited attack surface reported (0 entry points) is a strong positive, but it does not negate the risk posed by the unescaped output.
In conclusion, while the plugin has addressed past vulnerabilities and avoids several common pitfalls like direct SQL injection and dangerous function usage, the pervasive issue of unescaped output presents a critical security weakness. This plugin requires immediate attention to implement proper output escaping to mitigate the risk of XSS attacks. The lack of a larger attack surface is beneficial, but the unaddressed output sanitization is a significant flaw that outweighs this advantage.
Key Concerns
- 0% properly escaped output
- Past Medium severity CVE (CSRF)
Taxonomy Filter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Taxonomy filter <= 2.2.9 - Cross-Site Request Forgery via taxonomy_filter_save_main_settings()
Taxonomy Filter Code Analysis
Output Escaping
Taxonomy Filter Attack Surface
WordPress Hooks 13
Maintenance & Trust
Taxonomy Filter Maintenance & Trust
Maintenance Signals
Community Trust
Taxonomy Filter Alternatives
Search & Filter
search-filter
Search and Filtering for Custom Posts, Categories, Tags, Taxonomies, Post Dates and Post Types
Term Management Tools
term-management-tools
Allows you to merge terms, move terms between taxonomies, and set term parents, individually or in bulk.
Blog Filter Post Filtering
blog-filter
Blog Filter helps users display posts in filterable grid and masonry layouts. Organize content by categories or tags with customizable designs.
Widget Manager Light
widget-manager-light
Widget Manager lets you control on which pages widgets appear via nice and easy interface. Show or hide widgets. Display relevant content on your page …
GA Admin Taxonomy Search
ga-admin-taxonomy-search
Make it easy to search/filter items in your admin categories meta box.
Taxonomy Filter Developer Profile
4 plugins · 1K total installs
How We Detect Taxonomy Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taxonomy-filter/css/tfp.cssHTML / DOM Fingerprints
tfp-hide-blank-checkboxtfp-replace-checkbox<!-- THIS IS A HIDDEN TAXONOMY TERM --><!-- taxonomy_filter_terms_edit_form_fields --><!-- taxonomy_filter_terms_add_form_fields -->data-tfp-taxonomydata-tfp-termtaxonomy_filter_object