TG Product Tab Manager Security & Risk Analysis

wordpress.org/plugins/product-tab-manager

This plugin allows you to manage your Woocommerce product page tabs. Tabs can be renamed, removed and re-ordered on the single product page.

10 active installs v1.0.5 PHP + WP 3.0.1+ Updated Sep 25, 2024
product-page-tabsproduct-tabswoocommerce-product-tabs
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TG Product Tab Manager Safe to Use in 2026?

Generally Safe

Score 92/100

TG Product Tab Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The product-tab-manager plugin version 1.0.5 demonstrates a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, coupled with the fact that all detected SQL queries utilize prepared statements, suggests a proactive approach to common web vulnerabilities. Furthermore, the plugin has a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication checks or proper permission callbacks. This lack of readily accessible entry points significantly reduces the plugin's exposure to brute-force attacks and unauthorized access.

However, a notable concern arises from the output escaping, where only 64% of the 11 total outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is being reflected in these unescaped outputs. While the taint analysis found no unsanitized paths, the lack of comprehensive output escaping remains a weakness. The plugin also has no nonce checks, which, in combination with the unescaped outputs, could increase the risk of certain types of attacks if user input is processed insecurely.

In conclusion, product-tab-manager 1.0.5 is relatively secure due to its limited attack surface and secure SQL handling. The plugin's vulnerability history is clean, which is a positive sign. The primary areas for improvement are ensuring all output is properly escaped to mitigate XSS risks and considering the implementation of nonce checks for enhanced security, especially if any user input is processed through any unobserved functionality.

Key Concerns

  • Unescaped output detected
  • No nonce checks implemented
Vulnerabilities
None known

TG Product Tab Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TG Product Tab Manager Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

TG Product Tab Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
7 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

64% escaped11 total outputs
Attack Surface

TG Product Tab Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-tgptm.php:142
actionadmin_enqueue_scriptsincludes\class-tgptm.php:157
actionadmin_enqueue_scriptsincludes\class-tgptm.php:158
actionadmin_menuincludes\class-tgptm.php:161
actionadmin_initincludes\class-tgptm.php:164
actionwp_enqueue_scriptsincludes\class-tgptm.php:179
actionwp_enqueue_scriptsincludes\class-tgptm.php:180
filterwoocommerce_product_tabsincludes\class-tgptm.php:183
Maintenance & Trust

TG Product Tab Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 25, 2024
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

TG Product Tab Manager Developer Profile

Asif Aziz

2 plugins · 210 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TG Product Tab Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-tab-manager/admin/css/tgptm-admin.css/wp-content/plugins/product-tab-manager/admin/js/tgptm-admin.js
Script Paths
/wp-content/plugins/product-tab-manager/admin/js/tgptm-admin.js
Version Parameters
tgptm-admin?ver=tgptm?ver=

HTML / DOM Fingerprints

CSS Classes
tgptm-admin-page
HTML Comments
<!-- Settings fields for left quantity button --><!-- DEFAULT TABS -->
Data Attributes
data-tab="description"data-tab="additional_information"data-tab="reviews"
FAQ

Frequently Asked Questions about TG Product Tab Manager