Custom Product Tabs for WooCommerce Security & Risk Analysis

wordpress.org/plugins/simple-product-tabs-for-woocommerce

Discover the easy way to add extra tabs to your WooCommerce product pages.

0 active installs v1.2.1 PHP 7.4+ WP 6.0+ Updated Unknown
woocommerce-custom-tabwoocommerce-tabs-pluginwoocommerece-tabs
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Product Tabs for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Product Tabs for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "simple-product-tabs-for-woocommerce" v1.2.1 plugin exhibits a generally strong security posture, with a notable lack of discovered vulnerabilities in its history. The static analysis reveals a very small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. This significantly limits potential avenues for attack. The code also shows some positive security practices, including the presence of nonce checks and capability checks, and a reasonable percentage of SQL queries utilizing prepared statements. However, there are areas for improvement. The escaping of output is only 54% proper, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. The taint analysis, while finding no critical or high severity flows, analyzed a very small number of total flows (2), making it difficult to draw definitive conclusions about the plugin's overall robustness against advanced attacks. The absence of any recorded CVEs is a positive indicator, suggesting a history of good security development or successful patching, but the small sample size of the code analysis and taint flows means it's not a guarantee of current security.

Overall, the plugin is promising due to its limited attack surface and clean vulnerability history. The primary concern stems from the moderate rate of unescaped output, which presents a potential risk for XSS vulnerabilities. While the plugin does not appear to have critical flaws based on the provided data, the limited depth of the static and taint analysis means that more complex or subtle vulnerabilities might not have been detected. The plugin would benefit from a more comprehensive code review and potentially more rigorous testing to ensure all output is properly escaped and to further validate its security against a wider range of attack vectors.

Key Concerns

  • Moderate percentage of unescaped output
Vulnerabilities
None known

Custom Product Tabs for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Product Tabs for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
17
20 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

54% escaped37 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_tab_priority (src\Single_Tab.php:233)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom Product Tabs for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 36
filterplugin_row_metasrc\Admin\Admin_Controller.php:40
filterin_admin_headersrc\Admin\Admin_Controller.php:41
actionadmin_enqueue_scriptssrc\Admin\Admin_Controller.php:44
actionadmin_menusrc\Admin\Admin_Controller.php:47
filterwoocommerce_product_data_tabssrc\Admin\Product_Editor_Tabs.php:39
actionwoocommerce_product_data_panelssrc\Admin\Product_Editor_Tabs.php:40
actionsave_postsrc\Admin\Product_Editor_Tabs.php:41
filterwp_insert_post_datasrc\Admin\Product_Editor_Tabs.php:42
actionadmin_headsrc\Admin\Product_Editor_Tabs.php:43
filtersptb_use_the_content_filtersrc\Frontend\Frontend.php:78
filtersptb_filter_tab_contentsrc\Frontend\Frontend.php:79
filterwoocommerce_product_tabssrc\Frontend\Frontend.php:93
actionwp_enqueue_scriptssrc\Frontend\Frontend.php:96
actionplugins_loadedsrc\Plugin.php:79
actioninitsrc\Plugin.php:81
actionbefore_woocommerce_initsrc\Plugin.php:83
actionadmin_initsrc\Plugin_Setup.php:49
actioninitsrc\Post_Type.php:21
actionadmin_head-post.phpsrc\Post_Type.php:22
actionadmin_head-post-new.phpsrc\Post_Type.php:23
filtermanage_woo_product_tabs_posts_columnssrc\Post_Type.php:24
actionmanage_woo_product_tabs_posts_custom_columnsrc\Post_Type.php:25
filterpost_updated_messagessrc\Post_Type.php:26
filterpost_row_actionssrc\Post_Type.php:27
filtermanage_edit-woo_product_tabs_sortable_columnssrc\Post_Type.php:28
filterparent_filesrc\Post_Type.php:29
filtercustom_menu_ordersrc\Post_Type.php:30
filtermenu_ordersrc\Post_Type.php:31
filteruse_block_editor_for_post_typesrc\Post_Type.php:32
actionsave_postsrc\Post_Type.php:33
actionsave_postsrc\Post_Type.php:280
actionadd_meta_boxessrc\Single_Tab.php:14
actionsave_postsrc\Single_Tab.php:15
actionsave_postsrc\Single_Tab.php:16
actionsave_postsrc\Single_Tab.php:17
actionsave_postsrc\Single_Tab.php:18
Maintenance & Trust

Custom Product Tabs for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Custom Product Tabs for WooCommerce Developer Profile

Sharaz Shahid

5 plugins · 5K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Product Tabs for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-product-tabs-for-woocommerce/assets/js/admin.js/wp-content/plugins/simple-product-tabs-for-woocommerce/assets/css/admin.css
Script Paths
wp-content/plugins/simple-product-tabs-for-woocommerce/assets/js/admin.jswp-content/plugins/simple-product-tabs-for-woocommerce/assets/css/admin.css
Version Parameters
simple-product-tabs-for-woocommerce/assets/js/admin.js?ver=simple-product-tabs-for-woocommerce/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
sbsa-navsbsa-nav__itemsbsa-nav__item--activesbsa-nav__item-link
FAQ

Frequently Asked Questions about Custom Product Tabs for WooCommerce