
Widget Taxonomy Security & Risk Analysis
wordpress.org/plugins/widget-taxonomyWidget Taxonomy provides widget for post and custom post type taxonomy display. Taxonomy and Terms disply with listing options and post count of terms …
Is Widget Taxonomy Safe to Use in 2026?
Generally Safe
Score 85/100Widget Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The widget-taxonomy v1.0.0 plugin exhibits a mixed security posture. While the absence of known CVEs and a clean vulnerability history are positive indicators, the static analysis reveals several concerning practices. The plugin's attack surface appears minimal with no apparent entry points for direct exploitation. However, the use of `create_function`, a deprecated and often insecure function, is a significant concern. Furthermore, the low percentage of properly escaped output suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any of the data processed by the plugin originates from user input. The lack of nonce and capability checks, while not directly exploitable due to the limited attack surface, indicates a potential for privilege escalation or unauthorized actions if new entry points are introduced in future versions or if the existing code is leveraged indirectly.
Key Concerns
- Use of dangerous function: create_function
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Widget Taxonomy Security Vulnerabilities
Widget Taxonomy Release Timeline
Widget Taxonomy Code Analysis
Dangerous Functions Found
Output Escaping
Widget Taxonomy Attack Surface
WordPress Hooks 1
Maintenance & Trust
Widget Taxonomy Maintenance & Trust
Maintenance Signals
Community Trust
Widget Taxonomy Alternatives
Beautiful taxonomy filters
beautiful-taxonomy-filters
Supercharge your custom post type archives by letting visitors filter posts by their terms/categories. This plugin handles the whole thing for you!
Taxonomy Term Widget
taxonomy-term-widget
Add an advanced widget to your WordPress blog, like an extension of the Categories widget.
Posts By Taxonomy Widget
posts-by-taxonomy-widget
Display a list of taxonomy terms with recent posts in those terms in a simple to use widget
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Custom Taxonomy Order
custom-taxonomy-order-ne
Allows for the ordering of categories and custom taxonomy terms through a simple drag-and-drop interface
Widget Taxonomy Developer Profile
1 plugin · 10 total installs
How We Detect Widget Taxonomy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-taxonomy/widget-taxonomy.phpHTML / DOM Fingerprints
texonomy_widget_terms<![CDATA[]]><!-- ... -->id="ttwvalue="-1"var dropdown