
Epic Tap Widgets Security & Risk Analysis
wordpress.org/plugins/epic-tap-widgetsWidgets collection for TodoApuestas's blog network
Is Epic Tap Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Epic Tap Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "epic-tap-widgets" plugin v1.2.9 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the plugin's attack surface. Furthermore, the analysis indicates no use of dangerous functions, no raw SQL queries (all using prepared statements), no file operations, and no external HTTP requests, all of which are positive security indicators. The presence of a single nonce check is also a good sign, although the absence of capability checks is a notable omission.
However, a significant concern arises from the output escaping analysis. With 547 total outputs and only 47% properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities. This means that a large proportion of user-generated or dynamic content rendered by the plugin might not be properly sanitized, making it susceptible to malicious script injection. The taint analysis shows no critical or high-severity unsanitized flows, which is positive, but it only analyzed two flows, which may not be exhaustive.
The plugin's vulnerability history is clean, with no known CVEs. This suggests a history of responsible development and maintenance. Despite the clean history, the high percentage of unescaped output in the static analysis is a critical area that needs immediate attention. The plugin's strengths lie in its limited attack surface and secure database interaction, but the output escaping is a clear weakness that could be exploited.
Key Concerns
- Large percentage of unescaped output
- Lack of capability checks
Epic Tap Widgets Security Vulnerabilities
Epic Tap Widgets Release Timeline
Epic Tap Widgets Code Analysis
Output Escaping
Data Flow Analysis
Epic Tap Widgets Attack Surface
WordPress Hooks 9
Maintenance & Trust
Epic Tap Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Epic Tap Widgets Alternatives
Pronosticos Apuestas TAP
pronosticos-apuestas-tap
Permite gestionar pronosticos de apuestas
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Epic Tap Widgets Developer Profile
2 plugins · 40 total installs
How We Detect Epic Tap Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epic-tap-widgets/admin/css/epic-tap-widgets-admin.css/wp-content/plugins/epic-tap-widgets/admin/js/epic-tap-widgets-admin.js/wp-content/plugins/epic-tap-widgets/public/css/epic-tap-widgets-public.css/wp-content/plugins/epic-tap-widgets/public/js/epic-tap-widgets-public.jsplugin_dir_url( __FILE__ ) . 'js/epic-tap-widgets-admin.js'plugin_dir_url( __FILE__ ) . 'css/epic-tap-widgets-admin.css'plugin_dir_url( __FILE__ ) . 'js/epic-tap-widgets-public.js'plugin_dir_url( __FILE__ ) . 'css/epic-tap-widgets-public.css'epic-tap-widgets/admin/css/epic-tap-widgets-admin.css?ver=epic-tap-widgets/admin/js/epic-tap-widgets-admin.js?ver=epic-tap-widgets/public/css/epic-tap-widgets-public.css?ver=epic-tap-widgets/public/js/epic-tap-widgets-public.js?ver=HTML / DOM Fingerprints
epic-tap-widgets