
Term Taxonomy Converter Security & Risk Analysis
wordpress.org/plugins/term-taxonomy-converterCopy or convert terms between taxonomies.
Is Term Taxonomy Converter Safe to Use in 2026?
Generally Safe
Score 99/100Term Taxonomy Converter has a strong security track record. Known vulnerabilities have been patched promptly.
The 'term-taxonomy-converter' plugin exhibits a generally strong security posture in its current version (1.3.0), with no exposed AJAX handlers, REST API routes, shortcodes, or cron events lacking authentication or permission checks. The code analysis reveals a good practice of using prepared statements for all SQL queries and a high percentage of properly escaped output, mitigating common injection vulnerabilities. Furthermore, the presence of nonce and capability checks indicates an awareness of security best practices for protecting sensitive operations.
However, the taint analysis identified two flows with unsanitized paths. While these did not escalate to critical or high severity, they represent potential avenues for exploitation if not properly handled. The vulnerability history is also a point of concern; the plugin has one known medium severity CVE, an 'Improper Neutralization of Input During Web Page Generation' (Cross-site Scripting), which was last patched on January 21, 2025. While currently unpatched CVEs are zero, the existence of a past XSS vulnerability suggests that input sanitization might not always be consistently robust across all scenarios.
In conclusion, the plugin demonstrates a good foundation of security by design, especially in its handling of database interactions and output. The lack of direct entry points into the system is a significant strength. Nevertheless, the identified unsanitized paths in taint analysis and the history of an XSS vulnerability warrant attention to ensure all user-supplied data is rigorously validated and sanitized before use to prevent potential client-side attacks.
Key Concerns
- Taint flows with unsanitized paths
- Past medium severity CVE (XSS)
Term Taxonomy Converter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Term Taxonomy Converter <= 1.2 - Reflected Cross-Site Scripting
Term Taxonomy Converter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Term Taxonomy Converter Attack Surface
WordPress Hooks 2
Maintenance & Trust
Term Taxonomy Converter Maintenance & Trust
Maintenance Signals
Community Trust
Term Taxonomy Converter Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Complianz – Terms and Conditions
complianz-terms-conditions
Configure your own Terms and Conditions specific to your service or webshop.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
Categories to Tags Converter
wpcat2tag-importer
Convert existing categories to tags or tags to categories, selectively.
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
legal-pages
The best WordPress legal pages generator that comes with pre-made templates for GDPR, CCPA, DMCA, Privacy Policy, Terms & Conditions, Cookie Polic …
Term Taxonomy Converter Developer Profile
4 plugins · 2K total installs
How We Detect Term Taxonomy Converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.