
WP Recent Tags Security & Risk Analysis
wordpress.org/plugins/wp-recent-tagsProvide a widget to show the hot tags of your recent posts.
Is WP Recent Tags Safe to Use in 2026?
Generally Safe
Score 85/100WP Recent Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-recent-tags plugin version 0.1.1 presents a mixed security posture. On the positive side, it exhibits an extremely small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for compromise. Furthermore, the vulnerability history is clean, with no known CVEs, suggesting a potentially stable codebase in terms of publicly disclosed flaws.
However, there are significant areas of concern. A substantial percentage of SQL queries (7%) are not using prepared statements, which could lead to SQL injection vulnerabilities if the inputs are not properly sanitized. More critically, 37% of output escaping is not properly implemented, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities, especially since no nonce or capability checks are present for any entry points. The taint analysis, while limited in scope with only two flows analyzed, revealed two flows with unsanitized paths. This, combined with the lack of proper output escaping and capability checks, indicates potential vectors for malicious code execution or data manipulation.
In conclusion, while the plugin's limited attack surface and lack of historical vulnerabilities are strengths, the presence of unsanitized flows, raw SQL queries, and inadequate output escaping are serious weaknesses. The absence of any nonce or capability checks further exacerbates these risks, as there are no built-in protections against unauthorized access or manipulation. These issues suggest that while the plugin may not have been historically targeted, it contains exploitable flaws that could be leveraged by an attacker.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
WP Recent Tags Security Vulnerabilities
WP Recent Tags Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Recent Tags Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Recent Tags Maintenance & Trust
Maintenance Signals
Community Trust
WP Recent Tags Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
FF Tab Widget
ff-tab-widget
Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.
Post Tags Widget
post-tags-widget
Display tags for the current post in a widget.
SensitiveTagCloud
sensitive-tag-cloud
This wordpress plugin provides a tagcloud that shows tags depending of the current context (e.g. Category, Author, Tag, Post) only.
WP Recent Tags Developer Profile
2 plugins · 20 total installs
How We Detect WP Recent Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-recent-tags/wp_recent_tags.csswp-recent-tags/wp_recent_tags.css?ver=HTML / DOM Fingerprints
recent-tagsWP Recent Tags 0.1.1 (http://www.mashget.com) BeginWP Recent Tags Endname="recent-tags-title"name="recent-tags-rcposts-num"name="recent-tags-maxtags-num"name="recent-tags-style-cloud"name="recent-tags-style-list"