Plugin Pulse
← Pulse

Tainacan

by tainacan · Uncategorized

Also makes 3 other plugins · 2K+ installs across the portfolio →

A powerful and flexible open-source repository platform that brings digital collection management to WordPress.

How scoring works →
88 Health · A
Maintenance 100/100
Rating quality 87/100
Support 70/100

88 health vs 56 average across 16,376 Uncategorized plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

92 / 100

Excellent listing optimization

Biggest win: Rating quality

Update recency 100/100
WP compatibility 100/100
Rating quality 68/100
Listing tuning 100/100

To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

-33% vs prior 30d
33Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

1.1K

now · peak 2.3K

1.1K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Tainacan · #5459 you Tainacan URL Metadat · #13622 Tainacan Support for · #9076 Tainacan Extra View · #9398

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.1Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

6

releases in the last 12 months

2mo ago

latest release · v1.2.0

81

tagged releases on record

Recent releases

1.2.0 · 2mo ago1.1.0 · 4mo ago1.0.3 · 7mo ago1.0.2 · 9mo ago1.0.1 · 10mo ago1.0.0 · 10mo ago0.21.16 · 1.1y ago0.21.15 · 1.3y ago0.21.14 · 1.4y ago0.21.13 · 1.6y ago0.21.12 · 1.8y ago0.21.11 · 1.9y ago0.21.10 · 1.9y ago0.12.10 · 1.9y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 35% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.2 35%
v1.1 30%
v1.0 18%
v0.21 11%
v0.20 5.2%
Older / other versions 1.4%

Estimated active installs

The public count shows “1K+”. Our estimate pins where the real number sits.

tracked estimate
1K–2K ≈1.9K

Refined from the date this plugin crossed into its current band.

Install history · since 2019-10-06 · 1,428 observations

1KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. A declining trend compresses what a buyer would pay.

Details

Version
1.2.0
Last updated
2mo ago
Added
2018-05-25 · 8 yrs old
Requires WP
6.5
Tested up to
7.0.4
Requires PHP
7.4

Known vulnerabilities

via Wordfence Intelligence

17 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-07 CVE-2026-6230 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.0.3 Patched in 1.1.0
  2. 2026-05-28 CVE-2026-42740 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.0.3 Patched in 1.1.0
  3. 2025-12-20 CVE-2025-14043 Missing Authorization Affects <= 1.0.1 Patched in 1.0.2
  4. 2025-11-20 CVE-2025-12746 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.0.0 Patched in 1.0.1
  5. 2025-11-20 CVE-2025-12747 Files or Directories Accessible to External Parties Affects <= 1.0.0 Patched in 1.0.1
  6. 2025-05-16 CVE-2025-47512 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 0.21.14 Patched in 0.21.15
  7. 2025-01-22 CVE-2024-13236 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 0.21.12 Patched in 0.21.13
  8. 2024-10-10 CVE-2024-9221 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.21.10 Patched in 0.21.11
  9. 2024-10-09 CVE-2024-48040 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 0.21.8 Patched in 0.21.9
  10. 2024-07-30 CVE-2024-7135 Missing Authorization Affects <= 0.21.7 Patched in 0.21.8
  11. 2024-05-20 CVE-2024-34794 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.21.3 Patched in 0.21.4
  12. 2024-05-20 CVE-2024-4367 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.21.5 Patched in 0.21.6
  13. 2024-05-20 CVE-2024-34795 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.21.3 Patched in 0.21.4
  14. 2024-03-29 CVE-2024-30529 Missing Authorization Affects <= 0.20.7 Patched in 0.20.8
  15. 2024-02-26 CVE-2024-1435 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.20.6 Patched in 0.20.7
  16. 2023-11-20 CVE-2023-47848 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.20.4 Patched in 0.20.5
  17. 2022-05-24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.18.9 Patched in 0.18.10

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 20 languages, 5 at 90% or more

German 100%
German (Formal) 100%
Croatian 98%
Portuguese (Brazil) 98%
Spanish (Colombia) 95%
Dutch 84%
Ukrainian 82%
Catalan 73%
Albanian 68%
Spanish (Chile) 61%
Slovak 58%
Spanish (Spain) 57%
Greek 56%
Spanish (Mexico) 48%
Swedish 23%
French (France) 17%
Russian 10%
Spanish (Argentina) 5%
Italian 4%
Polish 3%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2023-10-06 900+ → 1K+ up after 184 days in tier
  2. 2023-04-05 800+ → 900+ up after 3 days in tier
  3. 2023-04-02 900+ → 800+ down after 1 days in tier
  4. 2023-04-01 800+ → 900+ up after 8 days in tier
  5. 2023-03-24 900+ → 800+ down after 5 days in tier
  6. 2023-03-19 800+ → 900+ up after 6 days in tier
  7. 2023-03-13 900+ → 800+ down after 81 days in tier
  8. 2022-12-22 800+ → 900+ up after 19 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Tainacan into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/tainacan" width="480" height="300" style="border:0" loading="lazy" title="Tainacan — Plugin Pulse"></iframe>
Preview card ↗

Tainacan: 1K+ active installs, 5.0★ (12 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/tainacan