WP Tabby – Ultimate WP Tabs Plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/tabby-free

WP Tabby is the cleanest, easy-to-use, lightweight, customizable, responsive WordPress tabs plugin to show your content in a beautiful way.

100 active installs v1.1.1 PHP 5.6+ WP 4.3+ Updated Nov 25, 2024
responsive-tabstabtabswordpress-tabswp-tabs
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Tabby – Ultimate WP Tabs Plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 92/100

WP Tabby – Ultimate WP Tabs Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'tabby-free' v1.1.1 exhibits a generally strong security posture based on the static analysis. It demonstrates good security practices by implementing nonce checks for all identified entry points and performing capability checks where appropriate. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The high percentage of properly escaped output and the moderate use of prepared statements in SQL queries are positive indicators. The lack of any historical vulnerabilities, including critical or high severity ones, suggests a consistent commitment to security by the developers.

However, there are a few areas that warrant attention. While the static analysis found no critical or high severity taint flows, the fact that 50% of SQL queries are not using prepared statements presents a potential risk for SQL injection vulnerabilities if user input is not meticulously sanitized before being incorporated into these queries. The presence of AJAX handlers without explicit authentication checks, although currently zero, is a critical detail to monitor. Any future additions to the AJAX handlers without robust authorization checks would significantly increase the attack surface and risk. The plugin's vulnerability history is a significant strength, indicating developer diligence. Overall, 'tabby-free' v1.1.1 is well-secured, with the primary area for improvement being the complete adoption of prepared statements for all SQL queries.

Key Concerns

  • SQL queries not using prepared statements
Vulnerabilities
None known

WP Tabby – Ultimate WP Tabs Plugin for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Tabby – Ultimate WP Tabs Plugin for WordPress Release Timeline

v1.1.1Current
v1.1.0
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WP Tabby – Ultimate WP Tabs Plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
74
676 escaped
Nonce Checks
9
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

90% escaped750 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
agm_export (includes\model\functions\actions.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Tabby – Ultimate WP Tabs Plugin for WordPress Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_agm-get-iconsincludes\model\functions\actions.php:50
authwp_ajax_agm-exportincludes\model\functions\actions.php:87
authwp_ajax_agm-importincludes\model\functions\actions.php:123
authwp_ajax_agm-resetincludes\model\functions\actions.php:150
authwp_ajax_agm-chosenincludes\model\functions\actions.php:189
authwp_ajax_agwp_tabby_preview_meta_boxincludes\preview\class-preview.php:26

Shortcodes 1

[wptabby] includes\class-wp-tabby.php:117
WordPress Hooks 28
actionadmin_initincludes\class-wp-tabby.php:58
actioninitincludes\class-wp-tabby.php:99
filterpost_updated_messagesincludes\class-wp-tabby.php:100
filtermanage_ag_wp_tabby_posts_columnsincludes\class-wp-tabby.php:101
actionmanage_ag_wp_tabby_posts_custom_columnincludes\class-wp-tabby.php:102
actionwp_enqueue_scriptsincludes\class-wp-tabby.php:111
actionwp_enqueue_scriptsincludes\class-wp-tabby.php:112
actionag_wp_tabby_action_tag_for_shortcodeincludes\class-wp-tabby.php:116
actionwp_enqueue_scriptsincludes\model\classes\abstract.class.php:20
actionadd_meta_boxesincludes\model\classes\metabox.class.php:51
actionsave_postincludes\model\classes\metabox.class.php:52
actionedit_attachmentincludes\model\classes\metabox.class.php:53
actionadmin_menuincludes\model\classes\options.class.php:106
actionadmin_bar_menuincludes\model\classes\options.class.php:107
actionnetwork_admin_menuincludes\model\classes\options.class.php:111
filteradmin_footer_textincludes\model\classes\options.class.php:487
actionafter_setup_themeincludes\model\classes\setup.class.php:47
actioninitincludes\model\classes\setup.class.php:48
actionswitch_themeincludes\model\classes\setup.class.php:49
actionadmin_enqueue_scriptsincludes\model\classes\setup.class.php:50
actionwp_enqueue_scriptsincludes\model\classes\setup.class.php:51
actionwp_headincludes\model\classes\setup.class.php:52
filteradmin_body_classincludes\model\classes\setup.class.php:53
actionadmin_initincludes\model\classes\taxonomy.class.php:41
actionadmin_footerincludes\model\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsincludes\model\fields\icon\icon.php:42
actionprint_default_editor_scriptsincludes\model\fields\wp_editor\wp_editor.php:62
actioninitplugin-main.php:32
Maintenance & Trust

WP Tabby – Ultimate WP Tabs Plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 25, 2024
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

WP Tabby – Ultimate WP Tabs Plugin for WordPress Developer Profile

AppGlut

8 plugins · 110 total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect WP Tabby – Ultimate WP Tabs Plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tabby-free/public/css/wptabby-public.css/wp-content/plugins/tabby-free/public/js/wptabby-public.js
Script Paths
/wp-content/plugins/tabby-free/public/js/wptabby-public.js
Version Parameters
tabby-free/public/css/wptabby-public.css?ver=tabby-free/public/js/wptabby-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
wptabby-navwptabby-content-wrapperwptabby-tab-content
Data Attributes
data-tabby-id
JS Globals
wptabby_frontend
Shortcode Output
[wptabby]
FAQ

Frequently Asked Questions about WP Tabby – Ultimate WP Tabs Plugin for WordPress