Tui's Category Intro For Archive Security & Risk Analysis

wordpress.org/plugins/tuis-category-intro-for-archive

This plugin has been written to insert a category introduction to each archive, based on its category title and despription.

10 active installs v1.00 PHP + WP 2.0.2+ Updated Jan 16, 2009
categoryformattingimagesmediathumbs
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tui's Category Intro For Archive Safe to Use in 2026?

Generally Safe

Score 85/100

Tui's Category Intro For Archive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The overall security posture of the "tuis-category-intro-for-archive" v1.00 plugin appears to be concerning, despite a lack of publicly disclosed vulnerabilities. While the plugin demonstrates good practices by avoiding dangerous functions, using prepared statements for SQL, and having no file operations or external HTTP requests, significant weaknesses are present. The most alarming finding is the unescaped output, indicating a strong possibility of Cross-Site Scripting (XSS) vulnerabilities. The presence of a taint flow with unsanitized paths, though not classified as critical or high, raises concerns about potential path traversal or file inclusion vulnerabilities if the entry points were to be exploited. The absence of nonce checks on AJAX handlers and the single capability check on the entire plugin, combined with a zero-attack surface reported for entry points without authentication, presents a confusing and potentially dangerous scenario. It is possible that the static analysis failed to identify all entry points or that the plugin relies on other mechanisms for protection that are not evident from this data. Given the unescaped output and the flagged taint flow, the plugin's security is not robust and warrants immediate attention.

Key Concerns

  • Unescaped output detected
  • Taint flow with unsanitized paths
  • Missing nonce checks on AJAX handlers
  • Limited capability checks across plugin
Vulnerabilities
None known

Tui's Category Intro For Archive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tui's Category Intro For Archive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
tui_cifa_options_page (tuis-category-intro-for-archive.php:108)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tui's Category Intro For Archive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menutuis-category-intro-for-archive.php:46
filterthe_contenttuis-category-intro-for-archive.php:49
actiontemplate_redirecttuis-category-intro-for-archive.php:56
Maintenance & Trust

Tui's Category Intro For Archive Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedJan 16, 2009
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tui's Category Intro For Archive Developer Profile

stephenbaugh

4 plugins · 40 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tui's Category Intro For Archive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tuis-category-intro-for-archive/tui_category_intro_for_archive.php
Version Parameters
tuis-category-intro-for-archive/tui_category_intro_for_archive.php?ver=

HTML / DOM Fingerprints

HTML Comments
Copyright 2009-2010 Stephen Baugh (email : stephen@stephenbaugh.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; either version 3 of the License, or+32 more
Data Attributes
id="content-wrapper"
FAQ

Frequently Asked Questions about Tui's Category Intro For Archive