
WP Tabs Security & Risk Analysis
wordpress.org/plugins/my-wp-tabsThis plugin will add an expand collapse Tabs feature inside a post or page.
Is WP Tabs Safe to Use in 2026?
Generally Safe
Score 99/100WP Tabs has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of my-wp-tabs v1.0 reveals a generally positive security posture, with no critical issues identified in terms of dangerous functions, unsanitized SQL queries, or unescaped output. The absence of file operations and external HTTP requests further contributes to a reduced attack surface. The code adheres to good practices by utilizing prepared statements for all SQL queries and properly escaping all output. However, the presence of 2 shortcodes without explicit capability checks or nonce validation introduces potential blind spots. While the static analysis did not find any direct vulnerabilities in these entry points, this lack of security controls warrants careful consideration, especially as attack surface increases. The vulnerability history indicates a single past medium-severity vulnerability related to Cross-Site Scripting (XSS), which was last addressed on March 3rd, 2025. The fact that it is currently unpatched is a significant concern, suggesting a potential for re-introduction of similar issues if not thoroughly addressed. Overall, the plugin demonstrates good coding practices in core areas but has a notable weakness in securing its shortcode entry points and a concerning history of an unpatched vulnerability.
Key Concerns
- Shortcodes without capability checks
- Shortcodes without nonce checks
- Unpatched medium vulnerability (XSS)
WP Tabs Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Tabs <= 2.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Tabs Code Analysis
WP Tabs Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
WP Tabs Maintenance & Trust
Maintenance Signals
Community Trust
WP Tabs Alternatives
No alternatives data available yet.
WP Tabs Developer Profile
10 plugins · 190 total installs
How We Detect WP Tabs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-wp-tabs/main.js/wp-content/plugins/my-wp-tabs/style.css/wp-content/plugins/my-wp-tabs/main.jsHTML / DOM Fingerprints
tab-holdershortcode-tabstabs-wrappertabsettabstab-boxtabs-containertab+1 moresohel_wp_tabs_counter<div id="tabs-" class="tab-holder shortcode-tabs clearfix tabs-"><div class="tab-hold tabs-wrapper"><ul id="tabs" class="tabset tabs"><li><a href="#">