
YQL Auto Tagger Security & Risk Analysis
wordpress.org/plugins/yql-auto-taggerThe plugin performs an analysis of your post text and suggests tags for you.
Is YQL Auto Tagger Safe to Use in 2026?
Generally Safe
Score 85/100YQL Auto Tagger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yql-auto-tagger plugin version 1.3.1 presents a significant security risk due to multiple critical vulnerabilities identified in its static analysis. The plugin has one unprotected AJAX handler, which serves as a direct entry point for attackers without any authentication or authorization checks. This is a major concern as it can be exploited to execute arbitrary actions within the WordPress environment. Furthermore, the plugin utilizes the `create_function` dangerous PHP function twice, which is known to be a source of vulnerabilities if not handled with extreme care. The lack of output escaping on all identified outputs is also a significant weakness, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on the AJAX handler exacerbates these risks, leaving the plugin highly susceptible to unauthorized access and malicious actions. While the plugin has a clean vulnerability history with no recorded CVEs, this should not be a reason for complacency, as the current static analysis reveals substantial inherent risks. The overall security posture is poor, with glaring omissions in fundamental security practices.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: create_function
- Unescaped output
- Missing nonce checks
- Missing capability checks
YQL Auto Tagger Security Vulnerabilities
YQL Auto Tagger Code Analysis
Dangerous Functions Found
Output Escaping
YQL Auto Tagger Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
YQL Auto Tagger Maintenance & Trust
Maintenance Signals
Community Trust
YQL Auto Tagger Alternatives
WP Calais Archive Tagger
wp-calais-archive-tagger
Goes through your archives and adds tags to your posts based on semantic analysis.
Already Existing Tags
already-existing-tags
Looks for already existing tags within your posts.
WP Calais Auto Tagger
calais-auto-tagger
The plugin performs semantic analysis of your posts to suggest tags using Open Calais.
Page Tagger
page-tagger
Page Tagger is a Wordpress plugin which lets you tag your pages just like you do with your posts. It adds a tagging widget in the page-editing view in …
TagPages
tagpages
Adds post-tags functionality for pages.
YQL Auto Tagger Developer Profile
2 plugins · 40 total installs
How We Detect YQL Auto Tagger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yql-auto-tagger/js.incHTML / DOM Fingerprints
yql_tagid="yql_taglist"id="yql_manual"id="yql_tag_box"id="yql_suggestions"yql_redisplay_tagsyql_add_manualyql_gettags