TNG WordPress Integration Security & Risk Analysis

wordpress.org/plugins/tng-wordpress-plugin

Integrates TNG (The Next Generation) genealogy software into Wordpress.

100 active installs v10.1.4 PHP + WP 2.5+ Updated Jan 1, 2024
bridgegenealogyintegrationthe-next-generationtng
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TNG WordPress Integration Safe to Use in 2026?

Generally Safe

Score 85/100

TNG WordPress Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of tng-wordpress-plugin v10.1.4 reveals several significant security concerns, despite the absence of known CVEs and apparent taint flow issues. The plugin exhibits a concerning lack of security best practices in its codebase. Specifically, none of its SQL queries utilize prepared statements, leaving it highly vulnerable to SQL injection attacks. Furthermore, all 56 output operations lack proper escaping, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks across all entry points, including file operations, indicates a broad susceptibility to various unauthorized actions and privilege escalation. The fact that there are no known vulnerabilities or historical issues might suggest the plugin is not widely used, or that prior security audits have not uncovered these fundamental flaws. In conclusion, while the plugin has a limited attack surface reported and no reported CVEs, the discovered coding deficiencies, particularly raw SQL queries and unescaped output, present a critical security risk that requires immediate attention and remediation.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping missing
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

TNG WordPress Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TNG WordPress Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
56
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped56 total outputs
Attack Surface

TNG WordPress Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionplugins_loadedtng.php:42
actioninittng.php:103
actionwidgets_inittng.php:104
actionadmin_menutng.php:105
actionadmin_noticestng.php:106
actiongenerate_rewrite_rulestng.php:107
filterlogin_redirecttng.php:118
actionlogin_headtng.php:120
actionregister_formtng.php:121
actionregister_posttng.php:122
actionuser_registertng.php:123
actiondelete_usertng.php:124
actionwp_authenticatetng.php:125
filterthe_poststng.php:128
actiontemplate_redirecttng.php:129
actionwp_headtng.php:130
actionloop_starttng.php:131
actionloop_endtng.php:132
actionwp_footertng.php:133
actionshutdowntng.php:134
filteruser_trailingslashittng.php:790
Maintenance & Trust

TNG WordPress Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJan 1, 2024
PHP min version
Downloads19K

Community Trust

Rating36/100
Number of ratings10
Active installs100
Developer Profile

TNG WordPress Integration Developer Profile

Mark Barnes

2 plugins · 120 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TNG WordPress Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tng-wordpress-plugin/tng.php/wp-content/plugins/tng-wordpress-plugin/admin.php
Version Parameters
tng-wordpress-plugin/tng.php?ver=tng-wordpress-plugin/admin.php?ver=

HTML / DOM Fingerprints

HTML Comments
Roger comment out the next line to remove Admin from WordPress Admin sidebar
FAQ

Frequently Asked Questions about TNG WordPress Integration