
User Taxonomies Security & Risk Analysis
wordpress.org/plugins/user-taxonomiesSimplify the process of adding support for custom taxonomies for Users. Just use register_taxonomy and everything else is taken care of.
Is User Taxonomies Safe to Use in 2026?
Generally Safe
Score 85/100User Taxonomies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-taxonomies" v1.0 plugin exhibits a generally positive security posture, largely due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The plugin also demonstrates some good practices by implementing capability checks. However, there are significant areas of concern that temper this positive outlook. The most prominent issue is the extremely low percentage of properly escaped output, indicating a high risk of cross-site scripting (XSS) vulnerabilities. While the static analysis shows no critical or high severity taint flows, the presence of a flow with unsanitized paths, combined with the inadequate output escaping, strongly suggests that malicious input could be rendered without proper sanitization, leading to potential script execution.
The lack of any recorded vulnerabilities in its history is a positive sign, suggesting responsible development practices or perhaps a limited attack surface to date. However, this history does not negate the clear risks identified in the current static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events limits the plugin's direct attack surface, which is a mitigating factor. Despite these strengths, the severe deficiency in output escaping creates a substantial risk that cannot be ignored. A plugin with such poor output sanitization is highly susceptible to XSS attacks, even if other security measures are in place.
Key Concerns
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks on entry points
User Taxonomies Security Vulnerabilities
User Taxonomies Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Taxonomies Attack Surface
WordPress Hooks 8
Maintenance & Trust
User Taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
User Taxonomies Alternatives
LH User Taxonomies
lh-user-taxonomies
Simplify the process of adding support for custom taxonomies for Users. Just use register_taxonomy and everything else is taken care of.
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
User Taxonomies Developer Profile
2 plugins · 90 total installs
How We Detect User Taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-taxonomies/user-taxonomies.phpHTML / DOM Fingerprints
name="user-taxonomies"value="user-taxonomies"