ZD Header Tags Security & Risk Analysis

wordpress.org/plugins/zd-header-tags

Put tags in between

70 active installs v2.1 PHP + WP 2.7+ Updated Oct 16, 2009
headerheader-tagstagszd-header-tags
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZD Header Tags Safe to Use in 2026?

Generally Safe

Score 85/100

ZD Header Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "zd-header-tags" v2.1 plugin exhibits a strong security posture from an attack surface perspective, with zero identified entry points that are unprotected. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without proper authorization checks is a significant positive. Furthermore, the plugin's code shows good practices in handling SQL queries exclusively through prepared statements and includes nonce and capability checks, indicating an awareness of basic WordPress security principles. However, a critical weakness is revealed in the output escaping. With 100% of outputs being unescaped, this presents a significant risk for cross-site scripting (XSS) vulnerabilities. The vulnerability history is clean, with no recorded CVEs, which, combined with the lack of taint analysis findings, suggests a current lack of known exploitable issues in this version. Despite the clean history and robust handling of SQL, the pervasive lack of output escaping represents a major blind spot and a clear and present danger for potential XSS attacks. The strength lies in its minimal attack surface and responsible SQL handling, but the weakness in output sanitization is a serious concern that overshadows these positives.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

ZD Header Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ZD Header Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
0 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped34 total outputs
Attack Surface

ZD Header Tags Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_headzd-header-tags.php:84
filterwp_titlezd-header-tags.php:87
actionadmin_menuzd-header-tags.php:90
actionadmin_menuzd-header-tags.php:93
actionsave_postzd-header-tags.php:96
Maintenance & Trust

ZD Header Tags Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 16, 2009
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

ZD Header Tags Developer Profile

Proloy Chakroborty

2 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZD Header Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zd-header-tags/zdstyle.css
Script Paths
/wp-content/plugins/zd-header-tags/js/header.js
Version Parameters
zd-header-tags/js/header.js?ver=zd-header-tags/zdstyle.css?ver=

HTML / DOM Fingerprints

Data Attributes
zdheadertag_noncename
FAQ

Frequently Asked Questions about ZD Header Tags