Tabbed Widgets Reloaded Security & Risk Analysis

wordpress.org/plugins/tabbed-widgets-reloaded

Create tab and accordion type widgets without writing a single line of code.

10 active installs v0.2 PHP + WP 2.9+ Updated Feb 8, 2012
accordiontabbed-widgetstabswidgetwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tabbed Widgets Reloaded Safe to Use in 2026?

Generally Safe

Score 85/100

Tabbed Widgets Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The 'tabbed-widgets-reloaded' plugin v0.2 exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high-severity issues within the code, such as dangerous functions, raw SQL queries, or unsanitized taint flows. The absence of file operations and external HTTP requests further reduces potential attack vectors. The plugin also has no recorded vulnerability history, which is a strong indicator of its past security diligence. However, a significant concern is the complete lack of nonce checks and capability checks across all entry points. While there are currently no exposed entry points (AJAX, REST API, shortcodes, cron events), this oversight represents a substantial latent risk. Should any of these entry points be introduced or become discoverable in future versions without proper authorization checks, they would be immediately vulnerable to various attacks.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • 50% of output not properly escaped
Vulnerabilities
None known

Tabbed Widgets Reloaded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tabbed Widgets Reloaded Release Timeline

v0.2Current
v0.1
Code Analysis
Analyzed Apr 16, 2026

Tabbed Widgets Reloaded Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Attack Surface

Tabbed Widgets Reloaded Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwidgets_inittabbed-widgets-reloaded.php:38
actionsidebar_admin_setuptabbed-widgets-reloaded.php:39
actionadmin_menutabbed-widgets-reloaded.php:40
actionwp_headtabbed-widgets-reloaded.php:41
actionwp_footertabbed-widgets-reloaded.php:42
actionwidgets_inittabbed-widgets-reloaded.php:44
actionadmin_noticestabbed-widgets-reloaded.php:53
actionadmin_enqueue_scriptstabbed-widgets-reloaded.php:124
Maintenance & Trust

Tabbed Widgets Reloaded Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedFeb 8, 2012
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tabbed Widgets Reloaded Developer Profile

Anupam Saha

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tabbed Widgets Reloaded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tabbed-widgets-reloaded/css/admin-style.css/wp-content/plugins/tabbed-widgets-reloaded/js/jquery-ui-custom.min.js/wp-content/plugins/tabbed-widgets-reloaded/js/jquery-cookie.min.js/wp-content/plugins/tabbed-widgets-reloaded/css/tabbed-widgets.css/wp-content/plugins/tabbed-widgets-reloaded/css/twenty-ten.css
Script Paths
/wp-content/plugins/tabbed-widgets-reloaded/js/jquery-ui-custom.min.js/wp-content/plugins/tabbed-widgets-reloaded/js/jquery-cookie.min.js
Version Parameters
tabbed-widgets-reloaded/css/tabbed-widgets.css?ver=0.1tabbed-widgets-reloaded/css/twenty-ten.css?ver=0.1tabbed-widgets-reloaded/js/jquery-ui-custom.min.jstabbed-widgets-reloaded/js/jquery-cookie.min.js

HTML / DOM Fingerprints

CSS Classes
tabbed-widget-container
HTML Comments
<!-- TW RELOADED Widget START --><!-- TW RELOADED Widget END -->
Data Attributes
data-rotatedata-rotate-timedata-random-startdata-start-tab
JS Globals
$rotateoptions
FAQ

Frequently Asked Questions about Tabbed Widgets Reloaded