Term Taxonomy Converter Security & Risk Analysis

wordpress.org/plugins/term-taxonomy-converter

Copy or convert terms between taxonomies.

500 active installs v1.3.0 PHP 7.4+ WP 5.0+ Updated Nov 28, 2025
categories-and-tags-convertercopy-taxonomiesduplicate-taxonomiestaxonomy-converterterms
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 21, 2025
Safety Verdict

Is Term Taxonomy Converter Safe to Use in 2026?

Generally Safe

Score 99/100

Term Taxonomy Converter has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 21, 2025Updated 4mo ago
Risk Assessment

The 'term-taxonomy-converter' plugin exhibits a generally strong security posture in its current version (1.3.0), with no exposed AJAX handlers, REST API routes, shortcodes, or cron events lacking authentication or permission checks. The code analysis reveals a good practice of using prepared statements for all SQL queries and a high percentage of properly escaped output, mitigating common injection vulnerabilities. Furthermore, the presence of nonce and capability checks indicates an awareness of security best practices for protecting sensitive operations.

However, the taint analysis identified two flows with unsanitized paths. While these did not escalate to critical or high severity, they represent potential avenues for exploitation if not properly handled. The vulnerability history is also a point of concern; the plugin has one known medium severity CVE, an 'Improper Neutralization of Input During Web Page Generation' (Cross-site Scripting), which was last patched on January 21, 2025. While currently unpatched CVEs are zero, the existence of a past XSS vulnerability suggests that input sanitization might not always be consistently robust across all scenarios.

In conclusion, the plugin demonstrates a good foundation of security by design, especially in its handling of database interactions and output. The lack of direct entry points into the system is a significant strength. Nevertheless, the identified unsanitized paths in taint analysis and the history of an XSS vulnerability warrant attention to ensure all user-supplied data is rigorously validated and sanitized before use to prevent potential client-side attacks.

Key Concerns

  • Taint flows with unsanitized paths
  • Past medium severity CVE (XSS)
Vulnerabilities
1

Term Taxonomy Converter Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24670medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Term Taxonomy Converter <= 1.2 - Reflected Cross-Site Scripting

Jan 21, 2025 Patched in 1.2.1 (92d)
Code Analysis
Analyzed Mar 16, 2026

Term Taxonomy Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
11
57 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

84% escaped68 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<term-taxonomy-converter> (term-taxonomy-converter.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Term Taxonomy Converter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuterm-taxonomy-converter.php:82
actionadmin_enqueue_scriptsterm-taxonomy-converter.php:83
Maintenance & Trust

Term Taxonomy Converter Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 28, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings6
Active installs500
Developer Profile

Term Taxonomy Converter Developer Profile

Dhanendran Rajagopal

4 plugins · 2K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
92 days
View full developer profile
Detection Fingerprints

How We Detect Term Taxonomy Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Term Taxonomy Converter