Categories to Tags Converter Security & Risk Analysis

wordpress.org/plugins/wpcat2tag-importer

Convert existing categories to tags or tags to categories, selectively.

50K active installs v0.6.3 PHP + WP 3.0+ Updated Oct 21, 2024
categories-and-tags-converterimporter
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Categories to Tags Converter Safe to Use in 2026?

Generally Safe

Score 92/100

Categories to Tags Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wpcat2tag-importer v0.6.3 plugin exhibits a generally strong security posture based on the static analysis. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) without authentication or permission checks is a significant strength. Furthermore, the plugin demonstrates good practices with the presence of nonce and capability checks, and a decent portion of SQL queries utilizing prepared statements.

However, there are areas for concern. The relatively low percentage of properly escaped output (44%) suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization in the remaining 56% of cases. While no critical or high severity taint flows were detected, this could be an artifact of the limited analysis or the plugin's functionality.

The plugin's vulnerability history is completely clean, with no recorded CVEs. This is a positive indicator, suggesting it has been developed with security in mind and has not historically been a target or source of vulnerabilities. In conclusion, while the plugin benefits from a small attack surface and a clean history, the significant proportion of unescaped output warrants careful attention and potential remediation to mitigate XSS risks.

Key Concerns

  • Significant portion of output not properly escaped
Vulnerabilities
None known

Categories to Tags Converter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Categories to Tags Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
35
28 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

44% escaped63 total outputs
Attack Surface

Categories to Tags Converter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitwpcat2tag-importer.php:492
Maintenance & Trust

Categories to Tags Converter Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedOct 21, 2024
PHP min version
Downloads1.8M

Community Trust

Rating86/100
Number of ratings16
Active installs50K
Developer Profile

Categories to Tags Converter Developer Profile

briancolinger

11 plugins · 113K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Categories to Tags Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpcat2tag-importer/wpcat2tag-importer.php
Version Parameters
wpcat2tag-importer/wpcat2tag-importer.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Categories to Tags Converter