
Terms Dictionary Security & Risk Analysis
wordpress.org/plugins/terms-dictionaryCreate a dictionary to your site in a couple of clicks.
Is Terms Dictionary Safe to Use in 2026?
Use With Caution
Score 64/100Terms Dictionary has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "terms-dictionary" plugin version 1.5.1 exhibits a mixed security posture. While it boasts a small attack surface with only one shortcode as an entry point and no AJAX or REST API endpoints exposed without authentication, several critical weaknesses are present. The most significant concern is the complete lack of output escaping for all 13 detected output points. This makes the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, as any user-supplied data displayed on the frontend could be manipulated to execute malicious scripts.
Furthermore, the plugin has a known vulnerability history, with one unpatched medium severity CVE related to XSS. This, combined with the static analysis findings of unsanitized paths in taint analysis, suggests a pattern of insecure input handling. The absence of nonce and capability checks on its limited entry points, coupled with the universal lack of output escaping, indicates a concerning disregard for fundamental web security practices. While the plugin uses prepared statements for its SQL queries, this is overshadowed by the severe output escaping and vulnerability history issues.
Key Concerns
- Unpatched Medium CVE
- All outputs unescaped
- Unsanitized paths in taint analysis
- No nonce checks
- No capability checks
Terms Dictionary Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Terms Dictionary <= 1.5.1 - Reflected Cross-Site Scripting
Terms Dictionary Code Analysis
Output Escaping
Data Flow Analysis
Terms Dictionary Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Terms Dictionary Maintenance & Trust
Maintenance Signals
Community Trust
Terms Dictionary Alternatives
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Heroic Glossary – Block for building Glossaries, Dictionaries and more
heroic-glossary
The best WordPress glossary builder plugin to create and manage your own glossary of terms.
Name Directory
name-directory
Name directory (glossary) with many options like multiple directories, integrated search, non-latin characters, recaptcha, HTML editor and many more.
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Encyclopedia / Glossary / Wiki
encyclopedia-lexicon-glossary-wiki-dictionary
Supercharged tool to build your own awesome Encyclopedia / Lexicon / Glossary / Wiki / Dictionary / Knowledge base / Directory / Vocabulary in no time
Terms Dictionary Developer Profile
4 plugins · 190 total installs
How We Detect Terms Dictionary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/terms-dictionary/td-styles.cssterms-dictionary/td-styles.css?ver=HTML / DOM Fingerprints
<!-- Terms Dictionary plugin -->