bdwebteam recent post tabs widget Security & Risk Analysis

wordpress.org/plugins/bdwebteam-recent-post-tabs-widget

bdwebteam recent post tabs widget that shows the post tabs of your site with excerpt limit.

20 active installs v1.0.2 PHP + WP 1.0.1+ Updated Jun 29, 2015
advanced-recent-post-tabsblog-postspopular-poostsrecent-postsreviews-poat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is bdwebteam recent post tabs widget Safe to Use in 2026?

Generally Safe

Score 85/100

bdwebteam recent post tabs widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "bdwebteam-recent-post-tabs-widget" v1.0.2 exhibits a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. Furthermore, all identified SQL queries are correctly implemented using prepared statements, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities. The absence of taint analysis findings further reinforces the impression of secure coding practices in these areas.

However, the analysis does highlight some areas for concern. The presence of the `create_function` dangerous function is a red flag, as it can be exploited for remote code execution if user-supplied data is passed into it without proper sanitization. Additionally, a significant portion of output is not properly escaped (42% escaped), meaning that cross-site scripting (XSS) vulnerabilities are a distinct possibility if user-controllable data is displayed without adequate sanitization. The complete lack of nonce checks and capability checks across all entry points is also a serious deficiency, leaving the plugin open to various attacks if any entry points were to be discovered or added in the future. The vulnerability history being clean is positive, but it does not negate the risks present in the current codebase.

In conclusion, while the plugin benefits from a small attack surface and good SQL practices, the use of `create_function`, insufficient output escaping, and a complete absence of authorization checks (nonces and capabilities) introduce significant security risks. Addressing these specific code-level issues should be the priority to improve the plugin's overall security.

Key Concerns

  • Dangerous function create_function used
  • Output not properly escaped (58% unsanitized)
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

bdwebteam recent post tabs widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

bdwebteam recent post tabs widget Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

bdwebteam recent post tabs widget Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
41
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("bdwebteam_recent_post_tabs_Wbdwebteam-recent-post-tabs-widget.php:41

Output Escaping

42% escaped71 total outputs
Attack Surface

bdwebteam recent post tabs widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwidgets_initbdwebteam-recent-post-tabs-widget.php:41
actionwp_print_stylesbdwebteam-recent-post-tabs-widget.php:70
actionsave_postbdwebteam-recent-post-tabs-widget.php:72
actionedit_postbdwebteam-recent-post-tabs-widget.php:73
actiondeleted_postbdwebteam-recent-post-tabs-widget.php:74
actionswitch_themebdwebteam-recent-post-tabs-widget.php:75
actioninitbdwebteam-recent-post-tabs-widget.php:78
actionwp_footerbdwebteam-recent-post-tabs-widget.php:79
Maintenance & Trust

bdwebteam recent post tabs widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 29, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

bdwebteam recent post tabs widget Developer Profile

Mahabub Hasan

5 plugins · 390 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect bdwebteam recent post tabs widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bdwebteam-recent-post-tabs-widget/css/bdwebteam-recent-tabs-widget.css/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/widget-tabs.js/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/functions.js
Script Paths
/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/widget-tabs.js/wp-content/plugins/bdwebteam-recent-post-tabs-widget/js/functions.js
Version Parameters
bdwebteam-recent-post-tabs-widget?ver=1.0.2

HTML / DOM Fingerprints

CSS Classes
bdwebteam-tabstabs-listtab-postscommenttabs-post-info
Data Attributes
data-tab
FAQ

Frequently Asked Questions about bdwebteam recent post tabs widget