Custom Product Tabs for WooCommerce WP All Import Add-on Security & Risk Analysis

wordpress.org/plugins/custom-product-tabs-wp-all-import-add-on

This add-on extends Custom Product Tabs for WooCommerce to work with WP All Import.

1K active installs v2.0.5 PHP + WP 3.8+ Updated Jun 24, 2023
product-tabstabswoowoocommercewp-all-import
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Product Tabs for WooCommerce WP All Import Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Product Tabs for WooCommerce WP All Import Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "custom-product-tabs-wp-all-import-add-on" v2.0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of its SQL queries using prepared statements and no external HTTP requests or shortcodes, significantly reducing common attack vectors. The absence of known vulnerabilities in its history is also a strong indicator of past diligence. However, the static analysis reveals several concerning areas. The presence of the `unserialize` function without any apparent sanitization or checks is a critical risk, as it can lead to remote code execution if fed malicious serialized data. Furthermore, only 50% of output escaping is properly handled, which could expose the application to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks, especially given it has file operations, raises concerns about potential unauthorized actions or modifications.

Key Concerns

  • Dangerous function unserialize used
  • Output escaping only 50% proper
  • No nonce checks
  • No capability checks
  • File operations present without auth checks
Vulnerabilities
None known

Custom Product Tabs for WooCommerce WP All Import Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Product Tabs for WooCommerce WP All Import Add-on Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:550

Output Escaping

50% escaped12 total outputs
Attack Surface

Custom Product Tabs for WooCommerce WP All Import Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionplugins_loadedcustom-product-tabs-wp-all-import-add-on.php:204
filterpmxi_addonsrapid-addon.php:143
filterwp_all_import_addon_parserapid-addon.php:144
filterwp_all_import_addon_importrapid-addon.php:145
filterwp_all_import_addon_saved_postrapid-addon.php:146
filterpmxi_options_optionsrapid-addon.php:147
filterwp_all_import_image_sectionsrapid-addon.php:148
filterpmxi_custom_typesrapid-addon.php:149
filterpmxi_post_list_orderrapid-addon.php:150
filterwp_all_import_post_type_imagerapid-addon.php:151
actionpmxi_extend_options_featuredrapid-addon.php:152
actionadmin_initrapid-addon.php:153
filterwp_all_import_acf_is_show_grouprapid-addon.php:218
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:901
filterwp_all_import_is_allow_import_imagesrapid-addon.php:904
filterwp_all_import_is_images_section_enabledrapid-addon.php:947
actionadmin_noticesrapid-addon.php:1142
Maintenance & Trust

Custom Product Tabs for WooCommerce WP All Import Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 24, 2023
PHP min version
Downloads28K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Custom Product Tabs for WooCommerce WP All Import Add-on Developer Profile

Evan Herman

15 plugins · 136K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
375 days
View full developer profile
Detection Fingerprints

How We Detect Custom Product Tabs for WooCommerce WP All Import Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-product-tabs-wp-all-import-add-on/css/style.css/wp-content/plugins/custom-product-tabs-wp-all-import-add-on/js/script.js
Script Paths
/wp-content/plugins/custom-product-tabs-wp-all-import-add-on/js/script.js
Version Parameters
custom-product-tabs-wp-all-import-add-on/css/style.css?ver=custom-product-tabs-wp-all-import-add-on/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
yikes-admin-noticeyikes-woo-products-tabs-wrap
HTML Comments
<!-- This tab will not be added to your products. This tab will be added as a saved tab. This tab will be added as a custom tab. You can customize the content. -->
Data Attributes
data-tab-iddata-tab-titledata-tab-content
JS Globals
RapidAddon
FAQ

Frequently Asked Questions about Custom Product Tabs for WooCommerce WP All Import Add-on