
WP-TagCanvas Security & Risk Analysis
wordpress.org/plugins/wp-tagcanvasWP-TagCanvas is a plugin using Javascript class which will draw and animate a HTML5 canvas based tag cloud. It support three shape
Is WP-TagCanvas Safe to Use in 2026?
Generally Safe
Score 85/100WP-TagCanvas has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-tagcanvas plugin, version 1.3.1, presents a mixed security picture. On the positive side, the plugin has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are very few direct entry points for attackers. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, and the code analysis indicates no dangerous functions or external HTTP requests. The use of prepared statements for all SQL queries is a significant strength, preventing common SQL injection vulnerabilities.
However, the static analysis reveals a critical weakness: none of the 25 identified output operations are properly escaped. This means that any dynamic content displayed by the plugin is susceptible to Cross-Site Scripting (XSS) attacks if it can be influenced by user input or other external data. The absence of nonce checks and capability checks, while not immediately exploitable due to the limited attack surface, leaves potential vulnerabilities open if new entry points were ever introduced or if a more complex interaction model was employed.
In conclusion, while the plugin's minimal attack surface and secure SQL practices are commendable, the widespread lack of output escaping is a serious concern that significantly elevates the risk of XSS vulnerabilities. The clean vulnerability history is positive but does not mitigate the immediate risks identified in the code analysis. Developers should prioritize addressing the unescaped output to improve the plugin's security posture.
Key Concerns
- 0% output escaping
- 0% capability checks
- 0% nonce checks
WP-TagCanvas Security Vulnerabilities
WP-TagCanvas Code Analysis
Output Escaping
WP-TagCanvas Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP-TagCanvas Maintenance & Trust
Maintenance Signals
Community Trust
WP-TagCanvas Alternatives
3D WP Tag Cloud-S
my-wp-tagcanvas
3D WP Tag Cloud-S draws and animates an HTML5 canvas based tag cloud.
3D WP Tag Cloud-M
3d-wp-tag-cloud-m
3D WP Tag Cloud-M creates multiple 3D tag clouds widget.
WI Games Shortcode
wi-games-shortcode
This plug-in will help you to place any game which you can find on wigames.net without problems
WI Games widget Plugin
wi-games-widget
This plugin will help you to smoothly integrate WI Games widget to your website.
3D Viewer – Display Interactive 3D Models
3d-viewer
3D Viewer lets you embed interactive 3D models and 360 product views on WordPress sites with support for GLB, GLTF, OBJ, STL, FBX, DAE, and BIM.
WP-TagCanvas Developer Profile
1 plugin · 40 total installs
How We Detect WP-TagCanvas
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tagcanvas/tagcanvas.js/wp-content/plugins/wp-tagcanvas/tagcanvas.jswp-tagcanvas/tagcanvas.js?ver=HTML / DOM Fingerprints
wrapid="tag_canvas"id="tag_html5"TagCanvastcolorolcolorreversespeedshape+6 more