
Author: António Andrade Security & Risk Analysis
wordpress.org/plugins/wp-tag-thisEnables your blog readers to suggest new post tags or upvote/downvote existing ones.
Is Author: António Andrade Safe to Use in 2026?
Generally Safe
Score 85/100Author: António Andrade has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-tag-this" v1.3 plugin exhibits a seemingly strong security posture at first glance, with no reported CVEs and a clean vulnerability history. Static analysis shows no direct attack surface like AJAX handlers, REST API routes, or shortcodes, and no dangerous functions or raw SQL queries. Taint analysis also found no critical or high-severity flows. This suggests the plugin developers have implemented basic security measures like using prepared statements for SQL and including nonce and capability checks in some areas. However, a significant concern arises from the output escaping. With 100% of the 14 detected output points being unescaped, this plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. Any data displayed by the plugin that originates from user input or external sources could be rendered directly in the browser without sanitization, allowing attackers to inject malicious scripts. While the lack of attack vectors is positive, the unescaped output represents a critical weakness that could be easily exploited if any user-controllable data is rendered by the plugin.
Key Concerns
- All output points are unescaped
Author: António Andrade Security Vulnerabilities
Author: António Andrade Code Analysis
Output Escaping
Data Flow Analysis
Author: António Andrade Attack Surface
WordPress Hooks 4
Maintenance & Trust
Author: António Andrade Maintenance & Trust
Maintenance Signals
Community Trust
Author: António Andrade Alternatives
TagPages
tagpages
Adds post-tags functionality for pages.
Laiser Tag
laiser-tag
Laiser Tag is an automated tagging plugin that uses the Open Calais API to generate tags for created content within a WordPress Site.
Laiser Tag Insights
laiser-tag-insights
Laiser Tag Insights is extended plugin that visualizes structured content performance through Google Webmaster data. (Re quires the Laiser Tag automat …
Laiser Tag Plus
laiser-tag-plus
Use Laiser Tag Plus to get semantic data to use as tags and photo for your posts.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Author: António Andrade Developer Profile
2 plugins · 100 total installs
How We Detect Author: António Andrade
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tag-this/wp-tag-this-ui.js/wp-content/plugins/wp-tag-this/wp-tag-this-ui.css/wp-content/plugins/wp-tag-this/wp-tag-this-ui.jsHTML / DOM Fingerprints
tag-thistagthis-inputtagthis-taglistvote-counttagthis-upvotetagthis-downvote Copyright 2012-2014 António Andrade (email : antonio@antonioandra.de) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or+11 moredata-tagdata-voteWPtagthis