TBS Scripture Tagger Security & Risk Analysis

wordpress.org/plugins/tbs-scripture-tagger

Automatically converts plain-text Bible references into interactive links with hoverable verse previews from The Bible Says.

0 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Jan 29, 2026
biblereferencesscripturetheologytooltip
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TBS Scripture Tagger Safe to Use in 2026?

Generally Safe

Score 100/100

TBS Scripture Tagger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of tbs-scripture-tagger v1.0.3 indicates a generally strong security posture. The absence of any identified dangerous functions, SQL queries that are not properly prepared, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the presence of nonce checks is a positive sign of defensive programming. The plugin's attack surface is zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, meaning there are no direct entry points for external interaction. The taint analysis revealing zero flows with unsanitized paths further reinforces this positive assessment.

Despite the excellent code signals, the complete lack of capability checks is a notable concern. While the attack surface is currently zero, if any new features are introduced that require user interaction or modification of data, the absence of capability checks could leave these new features vulnerable to privilege escalation or unauthorized access. The vulnerability history being entirely empty suggests a clean past, but this does not inherently guarantee future security. It's important to recognize that a lack of past vulnerabilities can sometimes be attributed to a lack of rigorous security auditing or limited exposure, rather than inherent security.

In conclusion, tbs-scripture-tagger v1.0.3 demonstrates a very clean codebase with excellent adherence to secure coding practices for existing functionalities. The primary weakness lies in the missing capability checks, which represent a potential future risk if the plugin's functionality expands or its exposure increases. The absence of any past vulnerabilities is a positive indicator, but it's crucial to maintain vigilance and implement robust authorization checks as the plugin evolves.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

TBS Scripture Tagger Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TBS Scripture Tagger Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

TBS Scripture Tagger Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface

TBS Scripture Tagger Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptstbs-scripture-tagger.php:132
actionadmin_menutbs-scripture-tagger.php:148
Maintenance & Trust

TBS Scripture Tagger Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads176

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TBS Scripture Tagger Developer Profile

thebiblesays

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TBS Scripture Tagger

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tbs-scripture-tagger/assets/scripts/TBS_ScriptTagger-min-v2.js
Script Paths
/wp-content/plugins/tbs-scripture-tagger/assets/scripts/TBS_ScriptTagger-min-v2.js
Version Parameters
TBS_ScriptTagger-min-v2.js?ver=

HTML / DOM Fingerprints

JS Globals
window.TBS.Tagger
FAQ

Frequently Asked Questions about TBS Scripture Tagger