Tabs in Post Editor Security & Risk Analysis

wordpress.org/plugins/tabs-in-post-editor

Write code in the WP post editor? Hate not being able to use [tab]s? Now you can.

500 active installs v1.1 PHP + WP 2.0+ Updated Oct 18, 2013
admindateeditpostposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tabs in Post Editor Safe to Use in 2026?

Generally Safe

Score 85/100

Tabs in Post Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'tabs-in-post-editor' plugin version 1.1 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identifiable attack surface points, such as AJAX handlers, REST API routes, or shortcodes, significantly reduces the potential for external exploitation. Furthermore, the code signals indicate a robust implementation, with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The lack of file operations and external HTTP requests also contributes to a secure design. The vulnerability history further reinforces this positive assessment, showing zero known CVEs, historical or current. This indicates a well-maintained and secure plugin that has not historically presented security risks.

While the plugin's current version appears highly secure, the complete absence of nonces and capability checks across all potential entry points (even though there are none currently identified) represents a theoretical weakness. If the plugin were to introduce new entry points in the future without proper authentication and authorization mechanisms, it could create vulnerabilities. However, based on the current data, this plugin appears to be a model of secure WordPress plugin development, with no immediate risks detected and a history of no security incidents.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Tabs in Post Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tabs in Post Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Tabs in Post Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_footertabs-in-editor.php:13
Maintenance & Trust

Tabs in Post Editor Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedOct 18, 2013
PHP min version
Downloads16K

Community Trust

Rating94/100
Number of ratings3
Active installs500
Developer Profile

Tabs in Post Editor Developer Profile

Aaron Butacov

6 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tabs in Post Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/tabs-in-post-editor/tabs-in-editor.php

HTML / DOM Fingerprints

CSS Classes
ed_button
HTML Comments
<!-- -->
Data Attributes
id="ed_tabs"value="Disable Tabs"
JS Globals
jQuery$
FAQ

Frequently Asked Questions about Tabs in Post Editor