WP Smart Taxonomy Security & Risk Analysis

wordpress.org/plugins/wp-smart-taxonomy

A cool new Wordpress plugin that helps you to make smart collection of posts.

10 active installs v1.1.0 PHP + WP 3.0+ Updated Aug 19, 2016
automaticcategoriescategorysmarttaxonomy
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Smart Taxonomy Safe to Use in 2026?

Generally Safe

Score 85/100

WP Smart Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-smart-taxonomy" v1.1.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of identified entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous function usage, no file operations, and no external HTTP requests, all of which are positive indicators. The fact that all SQL queries utilize prepared statements and the high percentage of properly escaped output further bolster its security. The plugin also has no recorded vulnerability history, suggesting a well-maintained and secure codebase over time.

While the static analysis indicates a very low risk, the complete absence of nonce and capability checks is a notable area for concern, as these are fundamental security mechanisms in WordPress. The taint analysis also showed no flows, which is excellent, but the absence of these checks could potentially allow for unforeseen issues if new entry points were introduced or if existing ones were previously overlooked. Overall, the plugin appears to be highly secure due to its minimal attack surface and good coding practices regarding SQL and output escaping. However, the lack of explicit capability and nonce checks represents a potential weakness that could be exploited in specific scenarios, although no such vulnerabilities have been identified to date.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Smart Taxonomy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Smart Taxonomy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped34 total outputs
Attack Surface

WP Smart Taxonomy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuadmin\class-dc-WP-Smart-Taxonomy-settings.php:13
actionadmin_initadmin\class-dc-WP-Smart-Taxonomy-settings.php:14
actionsettings_page_dc_WP_ST_general_tab_initadmin\class-dc-WP-Smart-Taxonomy-settings.php:17
actionadmin_enqueue_scriptsclasses\class-dc-WP-Smart-Taxonomy-admin.php:8
actiondc_WP_ST_dualcube_admin_footerclasses\class-dc-WP-Smart-Taxonomy-admin.php:10
actionadd_meta_boxesclasses\class-dc-WP-Smart-Taxonomy-admin.php:12
actionsave_postclasses\class-dc-WP-Smart-Taxonomy-admin.php:14
actionwp_import_set_post_termsclasses\class-dc-WP-Smart-Taxonomy-admin.php:17
actionpmxi_saved_postclasses\class-dc-WP-Smart-Taxonomy-admin.php:20
actioninitclasses\class-dc-WP-Smart-Taxonomy.php:33
Maintenance & Trust

WP Smart Taxonomy Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 19, 2016
PHP min version
Downloads3K

Community Trust

Rating86/100
Number of ratings4
Active installs10
Developer Profile

WP Smart Taxonomy Developer Profile

DualCube

4 plugins · 830 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect WP Smart Taxonomy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-smart-taxonomy/css/dc-wp-smart-taxonomy.css/wp-content/plugins/wp-smart-taxonomy/js/dc-wp-smart-taxonomy.js
Script Paths
/wp-content/plugins/wp-smart-taxonomy/js/dc-wp-smart-taxonomy.js
Version Parameters
wp-smart-taxonomy/css/dc-wp-smart-taxonomy.css?ver=wp-smart-taxonomy/js/dc-wp-smart-taxonomy.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp_smart_taxonomy_options
Data Attributes
name="smart_cat_settings[placeholder]"name="smart_cat_settings[is_enable]"name="smart_cat_settings[is_append]"name="smart_cat_settings[is_title]"name="smart_cat_settings[is_excerpt]"name="smart_cat_settings[is_content]"+1 more
JS Globals
DC_Wp_Smart_Taxonomy
FAQ

Frequently Asked Questions about WP Smart Taxonomy