
bdwebteam recent post tabs widget Security & Risk Analysis
wordpress.org/plugins/bdwebteam-recent-post-tabs-widgetbdwebteam recent post tabs widget that shows the post tabs of your site with excerpt limit.
Is bdwebteam recent post tabs widget Safe to Use in 2026?
Generally Safe
Score 85/100bdwebteam recent post tabs widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "bdwebteam-recent-post-tabs-widget" v1.0.2 exhibits a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. Furthermore, all identified SQL queries are correctly implemented using prepared statements, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities. The absence of taint analysis findings further reinforces the impression of secure coding practices in these areas.
However, the analysis does highlight some areas for concern. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for remote code execution if user-supplied data is passed into it without proper sanitization. Additionally, a significant portion of output is not properly escaped (42% escaped), meaning that cross-site scripting (XSS) vulnerabilities are a distinct possibility if user-controllable data is displayed without adequate sanitization. The complete lack of nonce checks and capability checks across all entry points is also a serious deficiency, leaving the plugin open to various attacks if any entry points were to be discovered or added in the future. The vulnerability history being clean is positive, but it does not negate the risks present in the current codebase.
In conclusion, while the plugin benefits from a small attack surface and good SQL practices, the use of `create_function`, insufficient output escaping, and a complete absence of authorization checks (nonces and capabilities) introduce significant security risks. Addressing these specific code-level issues should be the priority to improve the plugin's overall security.
Key Concerns
- Dangerous function create_function used
- Output not properly escaped (58% unsanitized)
- No nonce checks found
- No capability checks found
bdwebteam recent post tabs widget Security Vulnerabilities
bdwebteam recent post tabs widget Release Timeline
bdwebteam recent post tabs widget Code Analysis
Dangerous Functions Found
Output Escaping
bdwebteam recent post tabs widget Attack Surface
WordPress Hooks 8
Maintenance & Trust
bdwebteam recent post tabs widget Maintenance & Trust
Maintenance Signals
Community Trust
bdwebteam recent post tabs widget Alternatives
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
bdwebteam recent post tabs widget Developer Profile
5 plugins · 390 total installs
How We Detect bdwebteam recent post tabs widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bdwebteam-recent-post-tabs-widget/css/bdwebteam-recent-tabs-widget.css/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/widget-tabs.js/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/functions.js/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/widget-tabs.js/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/functions.jsbdwebteam-recent-post-tabs-widget?ver=1.0.2HTML / DOM Fingerprints
bdwebteam-tabstabs-listtab-postscommenttabs-post-infodata-tab