WP Responsive Tabs horizontal vertical and accordion Tabs Security & Risk Analysis

wordpress.org/plugins/responsive-horizontal-vertical-and-accordion-tabs

Create beautiful responsive tabs with a very easy interface. This plugin is all in one tabs plugin means it supports responsive horizontal, vertical a …

2K active installs v1.1.20 PHP + WP 3.0+ Updated Dec 3, 2025
accordion-tabshorizontal-tabsresponsive-tabsvertical-tabswp-tabs
97
A · Safe
CVEs total4
Unpatched0
Last CVEMar 28, 2024
Safety Verdict

Is WP Responsive Tabs horizontal vertical and accordion Tabs Safe to Use in 2026?

Generally Safe

Score 97/100

WP Responsive Tabs horizontal vertical and accordion Tabs has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Mar 28, 2024Updated 4mo ago
Risk Assessment

The plugin 'responsive-horizontal-vertical-and-accordion-tabs' version 1.1.20 presents a mixed security posture. While the static analysis indicates a good number of internal checks like nonce and capability checks, and the absence of dangerous functions, file operations, or external HTTP requests is positive, significant concerns arise from the output escaping. With only 20% of 680 output operations properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.

The vulnerability history is particularly concerning, with a total of 4 known CVEs, including one critical and three medium severity vulnerabilities. The common types of these past vulnerabilities, SQL Injection and XSS, align with the static analysis findings regarding poor output escaping. The fact that there are no currently unpatched vulnerabilities is a positive sign, suggesting recent fixes, but the pattern of past critical and medium issues indicates a recurring struggle with secure coding practices, particularly around input validation and output sanitization.

Overall, the plugin has a decent number of entry points, all of which appear to be protected by authentication checks according to the static analysis. However, the prevalent and historically common XSS and SQL injection vulnerabilities, coupled with the alarmingly low output escaping rate, paint a picture of a plugin that, while having some security measures in place, has critical weaknesses that could be exploited. Users should exercise caution and ensure this plugin is kept updated, though the history suggests a need for thorough auditing by the developers.

Key Concerns

  • Low output escaping rate (20%)
  • 1 critical historical vulnerability
  • 3 medium historical vulnerabilities
  • High percentage of SQL queries not prepared
Vulnerabilities
4

WP Responsive Tabs horizontal vertical and accordion Tabs Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
3

4 total CVEs

CVE-2024-30497critical · 9.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WP Responsive Tabs horizontal vertical and accordion Tabs <= 1.1.17 - Authenticated (Contributor+) SQL Injection

Mar 28, 2024 Patched in 1.1.18 (7d)
CVE-2024-27989medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Responsive Tabs horizontal vertical and accordion Tabs <= 1.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 15, 2024 Patched in 1.1.18 (6d)
CVE-2023-24409medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Responsive Tabs horizontal vertical and accordion Tabs <= 1.1.15 - Reflected Cross-Site Scripting

May 9, 2023 Patched in 1.1.16 (259d)
CVE-2023-2184medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Responsive Tabs horizontal vertical and accordion Tabs <= 1.1.15 - Reflected Cross-Site Scripting

Apr 19, 2023 Patched in 1.1.16 (279d)
Code Analysis
Analyzed Mar 16, 2026

WP Responsive Tabs horizontal vertical and accordion Tabs Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
19 prepared
Unescaped Output
543
137 escaped
Nonce Checks
7
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

83% prepared23 total queries

Output Escaping

20% escaped680 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
rt_wp_responsive_wp_admin_options_func (wp-best-responsive-tabs.php:436)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Responsive Tabs horizontal vertical and accordion Tabs Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_rt_get_tab_data_byidwp-best-responsive-tabs.php:23
noprivwp_ajax_rt_get_tab_data_byidwp-best-responsive-tabs.php:24

Shortcodes 1

[wrt_print_rt_wp_responsive_tabs] wp-best-responsive-tabs.php:21
WordPress Hooks 9
filterwidget_textwp-best-responsive-tabs.php:15
actionadmin_menuwp-best-responsive-tabs.php:16
actionwp_enqueue_scriptswp-best-responsive-tabs.php:20
actionplugins_loadedwp-best-responsive-tabs.php:22
filteruser_has_capwp-best-responsive-tabs.php:25
filtermap_meta_capwp-best-responsive-tabs.php:32
filterwidget_text_contentwp-best-responsive-tabs.php:3387
filterthe_contentwp-best-responsive-tabs.php:3388
filterrender_blockwp-best-responsive-tabs.php:3400
Maintenance & Trust

WP Responsive Tabs horizontal vertical and accordion Tabs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads41K

Community Trust

Rating100/100
Number of ratings5
Active installs2K
Developer Profile

WP Responsive Tabs horizontal vertical and accordion Tabs Developer Profile

Nks

19 plugins · 23K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
350 days
View full developer profile
Detection Fingerprints

How We Detect WP Responsive Tabs horizontal vertical and accordion Tabs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-horizontal-vertical-and-accordion-tabs/css/responsive-tabs.css/wp-content/plugins/responsive-horizontal-vertical-and-accordion-tabs/js/responsive-tabs.js
Script Paths
/wp-content/plugins/responsive-horizontal-vertical-and-accordion-tabs/js/responsive-tabs.js
Version Parameters
responsive-horizontal-vertical-and-accordion-tabs/css/responsive-tabs.css?ver=responsive-horizontal-vertical-and-accordion-tabs/js/responsive-tabs.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrt-tabs-containerwrt-tabs-main
Data Attributes
data-responsive-tabs
JS Globals
wrt_responsive_tabs_localiztion
REST Endpoints
/wp-json/responsive-tabs/v1/get_tab_data
Shortcode Output
[wrt_print_rt_wp_responsive_tabs]
FAQ

Frequently Asked Questions about WP Responsive Tabs horizontal vertical and accordion Tabs