Responsive Tabs Security & Risk Analysis

wordpress.org/plugins/responsive-tabs

A responsive & clean way to display your content. Create new tabs in no-time (custom type) and copy-paste the shortcode into any post/page.

5K active installs v4.0.11 PHP + WP 3.6+ Updated Jan 29, 2026
accordionresponsive-tabshortcodetabtabs
97
A · Safe
CVEs total5
Unpatched0
Last CVEJul 9, 2024
Safety Verdict

Is Responsive Tabs Safe to Use in 2026?

Generally Safe

Score 97/100

Responsive Tabs has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jul 9, 2024Updated 2mo ago
Risk Assessment

The "responsive-tabs" v4.0.11 plugin exhibits a generally good security posture in its current static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the presence of nonce and capability checks on its limited entry points suggests a thoughtful approach to access control.

However, the plugin's vulnerability history is a significant concern. With 5 known medium-severity CVEs, predominantly related to injection and cross-site scripting, it indicates a recurring pattern of vulnerabilities in how user input is handled or rendered. While there are no currently unpatched CVEs, the historical prevalence of these specific vulnerability types suggests a potential for future discoveries if the underlying coding practices are not rigorously reviewed and improved.

In conclusion, while the v4.0.11 version's static analysis shows adherence to many secure coding practices, the plugin's past indicates a need for ongoing vigilance and a deeper dive into the root causes of its historical vulnerabilities to ensure long-term security.

Key Concerns

  • Recurring medium-severity vulnerabilities (5 total)
  • Historical pattern of Injection and XSS vulnerabilities
Vulnerabilities
5

Responsive Tabs Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2023
2023
3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2024-4096medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Tabs <= 4.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 9, 2024 Patched in 4.0.11 (46d)
CVE-2024-1846medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Tabs <= 4.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 25, 2024 Patched in 4.0.7 (31d)
CVE-2024-1712medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Carousel Slider <= 2.2.6 - Authenticated (Editor+) Stored Cross-Site Scripting

Mar 25, 2024 Patched in 2.2.7 (16d)
CVE-2023-45635medium · 4.3Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Responsive Tabs < 4.0.6 - Authenticated (Contributor+) Content Injection

Oct 11, 2023 Patched in 4.0.6 (104d)
CVE-2021-36893medium · 4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Tabs <= 4.0.5 - Authenticated Stored Cross-Site Scripting

Apr 11, 2022 Patched in 4.0.6 (651d)
Code Analysis
Analyzed Mar 16, 2026

Responsive Tabs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
47 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped47 total outputs
Attack Surface

Responsive Tabs Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rtbs] inc\rtbs-shortcode.php:91
WordPress Hooks 14
actionadmin_enqueue_scriptsinc\rtbs-admin-scripts.php:4
actionwp_enqueue_scriptsinc\rtbs-front-scripts.php:4
actionadmin_initinc\rtbs-metaboxes-help.php:4
actionadmin_initinc\rtbs-metaboxes-pro.php:4
actionadmin_initinc\rtbs-metaboxes-settings.php:24
actionadmin_initinc\rtbs-metaboxes-tabs.php:4
actioninitinc\rtbs-post-type.php:4
filterpost_updated_messagesinc\rtbs-post-type.php:44
actionadmin_initinc\rtbs-pro-version-check.php:4
actionadmin_noticesinc\rtbs-pro-version-check.php:11
actionsave_postinc\rtbs-save-metaboxes.php:4
actionmanage_rtbs_tabs_posts_custom_columninc\rtbs-shortcode-column.php:4
filtermanage_rtbs_tabs_posts_columnsinc\rtbs-shortcode-column.php:22
actionplugins_loadedinc\rtbs-text-domain.php:4
Maintenance & Trust

Responsive Tabs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version
Downloads136K

Community Trust

Rating84/100
Number of ratings41
Active installs5K
Developer Profile

Responsive Tabs Developer Profile

WP Darko

8 plugins · 59K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
175 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Tabs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-tabs/css/rtbs_style.min.css/wp-content/plugins/responsive-tabs/js/rtbs.min.js/wp-content/plugins/responsive-tabs/dmb/dmb.min.css/wp-content/plugins/responsive-tabs/dmb/dmb.min.js/wp-content/plugins/responsive-tabs/css/rtbs_style.min.css/wp-content/plugins/responsive-tabs/js/rtbs.min.js
Script Paths
wp-content/plugins/responsive-tabs/dmb/dmb.min.jswp-content/plugins/responsive-tabs/js/rtbs.min.js
Version Parameters
responsive-tabs/css/rtbs_style.min.css?ver=responsive-tabs/js/rtbs.min.js?ver=responsive-tabs/dmb/dmb.min.css?ver=responsive-tabs/dmb/dmb.min.js?ver=responsive-tabs/css/rtbs_style.min.css?ver=responsive-tabs/js/rtbs.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtbsrtbs_tab_orirtbs_slugrtbs_inactive_tab_backgroundrtbs_breakpointrtbs_colorrtbs_menumobile_toggle+2 more
Data Attributes
data-tab
JS Globals
objectL10n
Shortcode Output
[rtbs name=
FAQ

Frequently Asked Questions about Responsive Tabs