WP-TagTip Security & Risk Analysis

wordpress.org/plugins/wp-tagtip

An sexy way to show a related post of one specific tag.

10 active installs v0.1 PHP + WP 2.5+ Updated Sep 28, 2009
relatedrelated-posttiptooltiptooltips
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-TagTip Safe to Use in 2026?

Generally Safe

Score 85/100

WP-TagTip has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The static analysis of wp-tagtip v0.1 reveals a remarkably clean codebase with no identified dangerous functions, SQL queries executed without prepared statements, unescaped output, file operations, external HTTP requests, or nonce/capability checks. The absence of any taint flows with unsanitized paths further strengthens this positive outlook. This indicates a strong adherence to secure coding practices within the analyzed version.

The vulnerability history for wp-tagtip is also empty, with zero known CVEs. This suggests a track record of security, or at the very least, a lack of publicly disclosed vulnerabilities. While this is a significant strength, it's important to note that the absence of vulnerabilities doesn't guarantee future security, especially for plugins with minimal public scrutiny or a very small user base.

In conclusion, based on the provided static analysis and vulnerability history, wp-tagtip v0.1 presents a very low security risk. The code itself appears to be robust and follows best practices. However, the extremely limited attack surface and the complete lack of any publicly disclosed vulnerabilities, while positive, could also indicate a plugin that is not widely used or actively scrutinized, which in itself is not a direct security weakness but a factor to consider in the broader ecosystem.

Vulnerabilities
None known

WP-TagTip Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-TagTip Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP-TagTip Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WP-TagTip Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.4
Last updatedSep 28, 2009
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP-TagTip Developer Profile

eduardosada

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-TagTip

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-tagtip/css/style.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips/vista.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips/coda.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips/blue.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips/rosita.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips/hulk.css/wp-content/plugins/wp-tagtip/js/sexy-tooltips.js/wp-content/plugins/wp-tagtip/js/relatedcore.js
Script Paths
http://ajax.googleapis.com/ajax/libs/mootools/1.2.3/mootools-yui-compressed.js
Version Parameters
wp-tagtip/js/sexy-tooltips/vista.css?ver=wp-tagtip/js/sexy-tooltips/coda.css?ver=wp-tagtip/js/sexy-tooltips/blue.css?ver=wp-tagtip/js/sexy-tooltips/rosita.css?ver=wp-tagtip/js/sexy-tooltips/hulk.css?ver=wp-tagtip/css/style.css?ver=wp-tagtip/js/sexy-tooltips.js?ver=wp-tagtip/js/relatedcore.js?ver=

HTML / DOM Fingerprints

CSS Classes
relatedspan
HTML Comments
<!-- relatedLink Start --><!-- relatedLink End -->
JS Globals
related
Shortcode Output
<span class="relatedspan">
FAQ

Frequently Asked Questions about WP-TagTip