
Tabs & Pills Security & Risk Analysis
wordpress.org/plugins/tabs-pillsTabs & Pills is responsive & the most easiest Tabs builder for WordPress. You can add unlimited tabs with different themes.
Is Tabs & Pills Safe to Use in 2026?
Generally Safe
Score 92/100Tabs & Pills has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tabs-pills' plugin v1.7 exhibits a mixed security posture, with some strong practices but a notable area of concern. The plugin benefits from a clean vulnerability history, with no recorded CVEs, suggesting a generally well-maintained codebase. The static analysis reveals robust SQL practices, with all queries utilizing prepared statements, and a significant majority of output being properly escaped. This indicates an awareness of common web vulnerabilities. However, the presence of one unprotected AJAX handler represents a significant security weakness. This handler is a direct entry point into the plugin's functionality that could be exploited by unauthenticated users, potentially leading to unauthorized actions or information disclosure depending on the handler's purpose. The absence of capability checks on this specific entry point further amplifies the risk, as it bypasses WordPress's built-in permission system.
While the plugin demonstrates good practices in areas like SQL and output escaping, the unprotected AJAX handler is a critical oversight that exposes it to potential attacks. The taint analysis did not reveal any exploitable flows, which is positive, but this does not negate the risk presented by the unprotected AJAX endpoint. The plugin has a relatively small attack surface, but the single unprotected entry point is a high-impact vulnerability. Overall, the plugin has strengths in its SQL and escaping but requires immediate attention to secure its AJAX functionality.
Key Concerns
- Unprotected AJAX handler
- Missing capability check on AJAX
- Low percentage of properly escaped output (84%)
Tabs & Pills Security Vulnerabilities
Tabs & Pills Release Timeline
Tabs & Pills Code Analysis
Output Escaping
Data Flow Analysis
Tabs & Pills Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Tabs & Pills Maintenance & Trust
Maintenance Signals
Community Trust
Tabs & Pills Alternatives
Tabs Responsive – With WooCommerce Product Tabs Extension
tabs-responsive
Tabs Responsive is the most easiest drag & drop Tabs builder for WordPress. You can add unlimited Tabs with unlimited color Scheme.
Product Tabs for WooCommerce
woocommerce-product-tabs
Discover the easy way to add extra tabs to your WooCommerce product pages.
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs
wp-expand-tabs-free
A customizable plugin to create and manage WooCommerce product tabs and WordPress tabs to organize content.
Gutena Tabs
gutena-tabs
Gutena Tabs is a simple and easy-to-use WordPress plugin which allows you to create beautiful tabs in your posts and pages.
Product Tabs Manager for WooCommerce
product-tabs-manager-for-woocommerce
With Product Tabs Manager for WooCommerce You can create any tabs for products that you want
Tabs & Pills Developer Profile
3 plugins · 30 total installs
How We Detect Tabs & Pills
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tabs-pills/admin/assets/js/cdlzr-tabsbox-admin.js/wp-content/plugins/tabs-pills/admin/assets/css/bootstrap.min.css/wp-content/plugins/tabs-pills/admin/assets/css/admin-tabs-css.css/wp-content/plugins/tabs-pills/admin/assets/css/fontawesome/css/all.min.css/wp-content/plugins/tabs-pills/admin/assets/js/custom-js.js/wp-content/plugins/tabs-pills/admin/assets/js/bootstrap.min.js/wp-content/plugins/tabs-pills/admin/assets/css/bootstrap-side-modals.css/wp-content/plugins/tabs-pills/admin/assets/css/jquery-linedtextarea.css+1 more/wp-content/plugins/tabs-pills/admin/assets/js/cdlzr-tabsbox-admin.js/wp-content/plugins/tabs-pills/admin/assets/js/custom-js.js/wp-content/plugins/tabs-pills/admin/assets/js/bootstrap.min.js/wp-content/plugins/tabs-pills/admin/assets/js/jquery-linedtextarea.jsHTML / DOM Fingerprints
cdlzr-tabs-box