
Tab – Accordion, FAQ Security & Risk Analysis
wordpress.org/plugins/tabbedTab allows you to create a simple tabs, responsive tab, animation tab, horizontal tab, vertical tab, circle tab, FAQ, accordion, animation accordion.
Is Tab – Accordion, FAQ Safe to Use in 2026?
Mostly Safe
Score 84/100Tab – Accordion, FAQ is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The "tabbed" v1.3.9 plugin exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries (99%) and output escaping (95%), several significant security concerns remain. The plugin exposes a considerable attack surface with 3 out of 4 entry points lacking authentication checks, making them vulnerable to unauthorized access. This is further exacerbated by the presence of 3 AJAX handlers without proper nonce checks, creating opportunities for Cross-Site Request Forgery (CSRF) attacks if they perform sensitive actions.
The vulnerability history shows a past high-severity vulnerability attributed to "Missing Authorization" in late 2021, which is currently patched. However, this pattern of missing authorization on entry points is a recurring theme that raises concern. The taint analysis reveals no critical or high-severity flows, which is a positive sign, indicating that data handled by the plugin is generally processed safely. Despite the past vulnerability being addressed, the static analysis findings suggest that the plugin's developers need to prioritize securing all entry points to prevent future exploits.
In conclusion, "tabbed" v1.3.9 has strengths in its data handling but weaknesses in its access control. The high number of unprotected AJAX handlers and shortcodes is a significant risk. While no current critical vulnerabilities are detected in the static analysis, the historical pattern and current findings warrant careful attention to implement proper authorization and nonce checks across all entry points.
Key Concerns
- Unprotected AJAX handlers
- Unprotected shortcode
- Missing nonce checks on AJAX
- Previous high severity CVE (Missing Authorization)
Tab – Accordion, FAQ Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tab – Accordion, FAQ < 1.3.2 - Unauthenticated Arbitrary Tab Modification
Tab – Accordion, FAQ Release Timeline
Tab – Accordion, FAQ Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tab – Accordion, FAQ Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Tab – Accordion, FAQ Maintenance & Trust
Maintenance Signals
Community Trust
Tab – Accordion, FAQ Alternatives
WP Responsive Tabs horizontal vertical and accordion Tabs
responsive-horizontal-vertical-and-accordion-tabs
Create beautiful responsive tabs with a very easy interface. This plugin is all in one tabs plugin means it supports responsive horizontal, vertical a …
Tabs Responsive – With WooCommerce Product Tabs Extension
tabs-responsive
Tabs Responsive is the most easiest drag & drop Tabs builder for WordPress. You can add unlimited Tabs with unlimited color Scheme.
Tab Ultimate
tabs-pro
Tab Shortcode Ultimate is yet another simple, responsive, lightweight jQuery tabs plugin for creating responsive tabbed panels with unlimited options …
Easy Tabs Block – Fast & Responsive Tabs with Built-in Smooth Accordion
easy-tabs-block
Add responsive tabbed content to posts, pages, and products. 70+ pre-built patterns, no code, and minimal load.
PE Panels
pe-panels
Show your posts and pages in tabbed or collapsible way !
Tab – Accordion, FAQ Developer Profile
7 plugins · 9K total installs
How We Detect Tab – Accordion, FAQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tabbed/Style/Tabs-Rich-Web-Widget.css/wp-content/plugins/tabbed/Scripts/Tabs-Rich-Web-Widget.js/wp-content/plugins/tabbed/Style/richwebicons.css/wp-content/plugins/tabbed/Scripts/pickr.js/wp-content/plugins/tabbed/Scripts/jquery.fonticonpicker.min.js/wp-content/plugins/tabbed/Scripts/notifIt.min.js/wp-content/plugins/tabbed/Style/monolith.min.css/wp-content/plugins/tabbed/Style/jquery.fonticonpicker.min.css+2 more/wp-content/plugins/tabbed/Scripts/Tabs-Rich-Web-Widget.js/wp-content/plugins/tabbed/Scripts/pickr.js/wp-content/plugins/tabbed/Scripts/jquery.fonticonpicker.min.js/wp-content/plugins/tabbed/Scripts/notifIt.min.jsHTML / DOM Fingerprints
rich_webrich_web-unlock-altdata-rwtabs-idrwtabs_object/wp-json/rw_tabs/v1/options[Rich_Web_Tabs id="