ML Responsive Tabs Shortcode Security & Risk Analysis

wordpress.org/plugins/mlr-tabs

Donate link: http://lillistone.me/2016/04/tab-demo/ Tags: text, tabs, php, plugin, shortcode, posts, audio, jquery Requires at least: 2.

10 active installs v0.1 PHP + WP + Updated Aug 27, 2016
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ML Responsive Tabs Shortcode Safe to Use in 2026?

Generally Safe

Score 85/100

ML Responsive Tabs Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The mlr-tabs plugin version 0.1 exhibits a mixed security posture. On the positive side, it shows excellent practices by having no known vulnerabilities, no dangerous functions, no file operations, no external HTTP requests, and importantly, all SQL queries utilize prepared statements. The presence of a nonce check and a sole shortcode as the only entry point also suggests a deliberate effort to limit the attack surface. However, a significant concern arises from the low rate of proper output escaping. With 47 total outputs and only 19% properly escaped, there's a high probability of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser. The absence of capability checks on the shortcode is another area of potential weakness, as it means the shortcode's functionality could be accessed by any logged-in user without proper authorization.

Key Concerns

  • Low output escaping rate (19%)
  • Missing capability checks on shortcode
Vulnerabilities
None known

ML Responsive Tabs Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ML Responsive Tabs Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped47 total outputs
Attack Surface

ML Responsive Tabs Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mlpt] inc\ml_product_tabs.php:428
WordPress Hooks 9
actioncontextual_helpinc\ml_product_tabs.php:775
actioninitinc\ml_product_tabs_custom.php:2
actionadd_meta_boxesinc\ml_product_tabs_custom.php:44
actionsave_postinc\ml_product_tabs_custom.php:45
filterwidget_textinc\ml_product_tabs_custom.php:359
actionplugins_loadedproduct_tabs.php:69
actionplugins_loadedproduct_tabs.php:72
actionadmin_enqueue_scriptsproduct_tabs.php:75
actionwp_enqueue_scriptsproduct_tabs.php:78
Maintenance & Trust

ML Responsive Tabs Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedAug 27, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

ML Responsive Tabs Shortcode Alternatives

No alternatives data available yet.

Developer Profile

ML Responsive Tabs Shortcode Developer Profile

ersatzpole

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ML Responsive Tabs Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mlr-tabs/js/ml.producttabs.admin.js/wp-content/plugins/mlr-tabs/css/admin_tabs.css/wp-content/plugins/mlr-tabs/js/ml.product.tabs.js/wp-content/plugins/mlr-tabs/js/imagesloaded.pkgd.min.js/wp-content/plugins/mlr-tabs/css/tabs.css
Script Paths
/wp-content/plugins/mlr-tabs/js/ml.producttabs.admin.js/wp-content/plugins/mlr-tabs/js/ml.product.tabs.js/wp-content/plugins/mlr-tabs/js/imagesloaded.pkgd.min.js
Version Parameters
mlr-tabs/style.css?ver=mlr-tabs/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
mlpt_img_iconmlpt_img_fullmlpt_audio_elementmlpt_video_element
Data Attributes
data-mlpt-id
JS Globals
mlpt_shortcode_tabs
Shortcode Output
[mlr-tabs]
FAQ

Frequently Asked Questions about ML Responsive Tabs Shortcode