
xili-tidy-tags Security & Risk Analysis
wordpress.org/plugins/xili-tidy-tagsxili-tidy-tags is a tool for grouping tags by semantic groups or by language and for creating tidy tag clouds.
Is xili-tidy-tags Safe to Use in 2026?
High Risk
Score 46/100xili-tidy-tags carries significant security risk with 4 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The xili-tidy-tags plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries and includes a substantial number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms. The static analysis reveals a relatively small attack surface with no immediately obvious unprotected entry points, and no critical or high-severity issues found in the taint analysis. However, a significant concern arises from its vulnerability history. With four known CVEs, two of which remain unpatched, and a recent vulnerability discovered in September 2025, this plugin has a recurring pattern of security flaws. The common vulnerability types noted (XSS and CSRF) suggest potential issues with input sanitization and state-changing actions. The moderate percentage of improperly escaped output also raises red flags for potential XSS vulnerabilities, even if not immediately identified as critical by the taint analysis.
Key Concerns
- Unpatched CVEs (2)
- Medium severity CVEs (4)
- Significant portion of output not properly escaped
- Bundled library (DataTables) may be outdated
xili-tidy-tags Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
xili-tidy-tags <= 1.12.06 - Authenticated (Contributor+) Stored Cross-Site Scripting
xili-tidy-tags <= 1.12.06 - Reflected Cross-Site Scripting
xili-tidy-tags <= 1.12.04 - Reflected Cross-Site Scripting
xili-tidy-tags <= 1.12.03 - Cross-Site Request Forgery
xili-tidy-tags Release Timeline
xili-tidy-tags Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
xili-tidy-tags Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
xili-tidy-tags Maintenance & Trust
Maintenance Signals
Community Trust
xili-tidy-tags Alternatives
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Tags All In One
tags-all-in-one
Display a customizable tag cloud from selected taxonomies with various sorting and styling options.
Pixel Clusters
pixel-clusters
Create beautiful, responsive post clusters with shortcodes or Gutenberg blocks. Display posts, categories, tags, custom post types, and WooCommerce pr …
Archive Post Order Plus
archive-post-order-plus
A plugin that sets the display order of posts. 投稿の表示順を設定するプラグイン。
Kntnt's Any Term for Beaver Builder Page Builder
kntnts-bb-any-term
WordPress plugin that adds special purpose term to every taxonomy (including categories and tags) that makes taxonomy filters in post modules of Beave …
xili-tidy-tags Developer Profile
4 plugins · 2K total installs
How We Detect xili-tidy-tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xili-tidy-tags/xili-tidy-tags.css/wp-content/plugins/xili-tidy-tags/xili-tidy-tags.jsxili-tidy-tags/xili-tidy-tags.css?ver=xili-tidy-tags/xili-tidy-tags.js?ver=HTML / DOM Fingerprints
xili-tidy-tags-cloud-widgetdata-tt-widget-iddata-tt-post-iddata-tt-tag-iddata-tt-term-taxonomydata-tt-term-iddata-tt-tag-link+2 morexili_tidy_tags_options[xili_tidy_tags_cloud]