
Post Metaboxes Tabs Security & Risk Analysis
wordpress.org/plugins/post-metaboxes-tabsGroups mataboxes when editing post/page in administration backend to tabs according to metabox name pattern Tab/Metabox.
Is Post Metaboxes Tabs Safe to Use in 2026?
Generally Safe
Score 85/100Post Metaboxes Tabs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'post-metaboxes-tabs' v0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no detected dangerous functions, file operations, external HTTP requests, or SQL queries that are not using prepared statements. Furthermore, there is no recorded vulnerability history, suggesting a relatively clean past. The attack surface appears minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and critically, none of these are reported as unprotected.
However, there are significant concerns stemming from the output escaping and nonce/capability checks. The analysis indicates that 100% of the outputs are not properly escaped, presenting a high risk of cross-site scripting (XSS) vulnerabilities. Additionally, the complete absence of nonce and capability checks across all potential entry points means that even if an attack surface existed, it would be entirely unprotected against unauthorized actions or privilege escalation. The lack of taint analysis results (0 flows analyzed) is also a weakness, as it means sophisticated injection vulnerabilities might have been missed.
In conclusion, while the plugin has a clean history and a seemingly small attack surface, the critical lack of output escaping and authorization checks creates a severe risk of XSS and unauthorized access. The absence of taint analysis further clouds the security picture. The current version of this plugin should be treated with extreme caution.
Key Concerns
- No output escaping implemented
- No nonce checks implemented
- No capability checks implemented
- Taint analysis not performed
Post Metaboxes Tabs Security Vulnerabilities
Post Metaboxes Tabs Code Analysis
Output Escaping
Post Metaboxes Tabs Attack Surface
WordPress Hooks 1
Maintenance & Trust
Post Metaboxes Tabs Maintenance & Trust
Maintenance Signals
Community Trust
Post Metaboxes Tabs Alternatives
Custom Posts Per Page
custom-posts-per-page
Custom Posts Per Page provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different views.
Custom Posts Per Page Reloaded
custom-posts-per-page-reloaded
Custom Posts Per Page Reloaded provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different …
Tabify Edit Screen
tabify-edit-screen
Enable tabs in the edit screen and manage them from the back-end.
Get page IDs
get-page-ids
Fix some theme author mess.
Multi Tab
multi-tab
Creates a button in the WordPress admin that allows you to open multiple (check-marked) posts / pages / products (WooCommerce) at once.
Post Metaboxes Tabs Developer Profile
1 plugin · 10 total installs
How We Detect Post Metaboxes Tabs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-metaboxes-tabs/tabs.css/wp-content/plugins/post-metaboxes-tabs/tabs.js/wp-content/plugins/post-metaboxes-tabs/tabs.jspost-metaboxes-tabs/tabs.css?ver=post-metaboxes-tabs/tabs.js?ver=