
Archive Post Tabs Security & Risk Analysis
wordpress.org/plugins/archive-post-tabsArchive Post Tabs plugin is used to show list and grid view of the archive posts with months and years tabs. This plugin allows to created unlimited w …
Is Archive Post Tabs Safe to Use in 2026?
Generally Safe
Score 85/100Archive Post Tabs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The archive-post-tabs plugin version 1.0 exhibits a mixed security posture. While the absence of known CVEs and critical taint flows is a positive sign, indicating a lack of historically exploitable flaws and immediate critical code vulnerabilities, there are significant areas of concern. The presence of two AJAX handlers without authentication checks creates a notable attack vector, potentially allowing unauthorized users to trigger plugin functionality. Furthermore, the relatively low percentage of properly escaped output (57%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's interaction with user-generated content that might be displayed.
The vulnerability history is reassuring, showing no recorded past exploits, which could imply diligent maintenance or simply good fortune. However, this should not overshadow the immediate risks identified in the static analysis. The plugin relies on nonce checks for its AJAX handlers, but the lack of capability checks for all entry points is a missed opportunity for robust authorization. The plugin's attack surface is moderately sized with 7 total entry points, but the two unprotected AJAX handlers are the most pressing issues. The SQL query analysis shows a reliance on prepared statements for some queries, but the overall percentage suggests that direct SQL execution might still occur in a way that is less secure.
In conclusion, while the plugin does not appear to have a history of severe vulnerabilities, the current static analysis reveals immediate security weaknesses. The unprotected AJAX handlers and potential for XSS due to insufficient output escaping are the most critical points to address. The lack of capability checks on all entry points is a general best practice that is not being followed. Addressing these issues is crucial to improving the plugin's overall security.
Key Concerns
- AJAX handlers without auth checks
- Low output escaping percentage
- No capability checks on entry points
Archive Post Tabs Security Vulnerabilities
Archive Post Tabs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Archive Post Tabs Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Archive Post Tabs Maintenance & Trust
Maintenance Signals
Community Trust
Archive Post Tabs Alternatives
Advanced Posts/Page
advanced-posts-per-page
Fine grained control of how many of your posts appear on each of the various WordPress archive pages.
Expanding Archives
expanding-archives
This plugin adds a new widget where you can view your old posts by expanding certain years and months.
Post Type Archive Descriptions
post-type-archive-descriptions
Enables an editable description to display on post type archive pages. Show the description with WordPress's the_archive_description() function t …
Smart Archives Reloaded
smart-archives-reloaded
Easily display posts grouped by year and month, in one or more elegant formats
Custom Posts Per Page
custom-posts-per-page
Custom Posts Per Page provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different views.
Archive Post Tabs Developer Profile
6 plugins · 200 total installs
How We Detect Archive Post Tabs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/archive-post-tabs/assets/css/admin-archivesposttab.css/wp-content/plugins/archive-post-tabs/assets/js/admin-archivesposttab.js/wp-content/plugins/archive-post-tabs/assets/css/archivesposttab.css/wp-content/plugins/archive-post-tabs/assets/js/archivesposttab.js/wp-content/plugins/archive-post-tabs/assets/js/admin-archivesposttab.js/wp-content/plugins/archive-post-tabs/assets/js/archivesposttab.jsHTML / DOM Fingerprints
avptab-archives-post-tabsdata-templatedata-widget-titledata-date-formatdata-number-of-post-displaydata-title-text-colordata-panel-text-color+7 morearchivesposttab