
TNG WordPress Integration Security & Risk Analysis
wordpress.org/plugins/tng-wordpress-pluginIntegrates TNG (The Next Generation) genealogy software into Wordpress.
Is TNG WordPress Integration Safe to Use in 2026?
Generally Safe
Score 85/100TNG WordPress Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of tng-wordpress-plugin v10.1.4 reveals several significant security concerns, despite the absence of known CVEs and apparent taint flow issues. The plugin exhibits a concerning lack of security best practices in its codebase. Specifically, none of its SQL queries utilize prepared statements, leaving it highly vulnerable to SQL injection attacks. Furthermore, all 56 output operations lack proper escaping, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks across all entry points, including file operations, indicates a broad susceptibility to various unauthorized actions and privilege escalation. The fact that there are no known vulnerabilities or historical issues might suggest the plugin is not widely used, or that prior security audits have not uncovered these fundamental flaws. In conclusion, while the plugin has a limited attack surface reported and no reported CVEs, the discovered coding deficiencies, particularly raw SQL queries and unescaped output, present a critical security risk that requires immediate attention and remediation.
Key Concerns
- SQL queries not using prepared statements
- Output escaping missing
- Missing nonce checks
- Missing capability checks
TNG WordPress Integration Security Vulnerabilities
TNG WordPress Integration Code Analysis
SQL Query Safety
Output Escaping
TNG WordPress Integration Attack Surface
WordPress Hooks 21
Maintenance & Trust
TNG WordPress Integration Maintenance & Trust
Maintenance Signals
Community Trust
TNG WordPress Integration Alternatives
Single Sign On For TNG
single-sign-on-for-tng
Single Sign On For TNG automates the login to the genealogy program TNG by Darrin Lithgoe.
WP phpBB Bridge
wp-phpbb-bridge
Shares user authentication with phpBB3, by forcing phbBB to handle all the authentication.
BridgeDD
bridgedd
BridgeDD has been discontinued.
BigAmbitions Membership & Login Bridge for GlueUp
bigambitions-glueup-bridge
Professional membership validator and login bridge for organizations using the GlueUp platform.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
TNG WordPress Integration Developer Profile
2 plugins · 120 total installs
How We Detect TNG WordPress Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tng-wordpress-plugin/tng.php/wp-content/plugins/tng-wordpress-plugin/admin.phptng-wordpress-plugin/tng.php?ver=tng-wordpress-plugin/admin.php?ver=HTML / DOM Fingerprints
Roger comment out the next line to remove Admin from WordPress Admin sidebar