TG Customized Tags Security & Risk Analysis

wordpress.org/plugins/tg-customized-tags

Display fully customized and configurable tags, categories or other taxonomy in tag-cloud with widget and shortcodes.

90 active installs v1.0 PHP + WP 3.0.1+ Updated Jul 30, 2015
categoriescategoryconfigurabletagtags
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TG Customized Tags Safe to Use in 2026?

Generally Safe

Score 85/100

TG Customized Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "tg-customized-tags" v1.0 plugin presents a mixed security posture. On the positive side, the plugin exhibits excellent practices regarding SQL queries, utilizing prepared statements exclusively and showing no known vulnerabilities or CVEs. The absence of file operations, external HTTP requests, and dangerous function calls further strengthens its current perceived security. However, significant concerns arise from the code analysis. The plugin has a low percentage of properly escaped output (11%), indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce checks or capability checks on its entry points (shortcodes in this case) is a major oversight, potentially allowing unauthorized actions or information disclosure if these shortcodes interact with sensitive data or functionality. The absence of taint analysis results is noted but doesn't detract from the existing concerns identified. While the plugin has no known historical vulnerabilities, the identified output escaping and authorization issues represent clear and present risks that need immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

TG Customized Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TG Customized Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped27 total outputs
Attack Surface

TG Customized Tags Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[tg_customized_tags_default] tg-customized-tags.php:533
[tg_customized_tags_current] tg-customized-tags.php:535
WordPress Hooks 3
actionadmin_menutg-customized-tags.php:13
actionadmin_inittg-customized-tags.php:56
filterwidget_tag_cloud_argstg-customized-tags.php:483
Maintenance & Trust

TG Customized Tags Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 30, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs90
Developer Profile

TG Customized Tags Developer Profile

Ashok Dhamija

3 plugins · 340 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TG Customized Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tg-customized-tags/tg-customized-tags.css
Version Parameters
tg-customized-tags/tg-customized-tags.css?ver=

HTML / DOM Fingerprints

Data Attributes
name="tg_customized_tags_options[number]"name="tg_customized_tags_options[unit]"name="tg_customized_tags_options[smallest]"name="tg_customized_tags_options[largest]"name="tg_customized_tags_options[taxonomy]"name="tg_customized_tags_options[format]"+5 more
Shortcode Output
[tg_customized_tags_default][tg_customized_tags_current]
FAQ

Frequently Asked Questions about TG Customized Tags