Tabs & Pills Security & Risk Analysis

wordpress.org/plugins/tabs-pills

Tabs & Pills is responsive & the most easiest Tabs builder for WordPress. You can add unlimited tabs with different themes.

10 active installs v1.7 PHP 5.6+ WP 5.0+ Updated Jun 24, 2024
responsive-tabstabtabstabs-contentwoocommerce-tabs
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tabs & Pills Safe to Use in 2026?

Generally Safe

Score 92/100

Tabs & Pills has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'tabs-pills' plugin v1.7 exhibits a mixed security posture, with some strong practices but a notable area of concern. The plugin benefits from a clean vulnerability history, with no recorded CVEs, suggesting a generally well-maintained codebase. The static analysis reveals robust SQL practices, with all queries utilizing prepared statements, and a significant majority of output being properly escaped. This indicates an awareness of common web vulnerabilities. However, the presence of one unprotected AJAX handler represents a significant security weakness. This handler is a direct entry point into the plugin's functionality that could be exploited by unauthenticated users, potentially leading to unauthorized actions or information disclosure depending on the handler's purpose. The absence of capability checks on this specific entry point further amplifies the risk, as it bypasses WordPress's built-in permission system.

While the plugin demonstrates good practices in areas like SQL and output escaping, the unprotected AJAX handler is a critical oversight that exposes it to potential attacks. The taint analysis did not reveal any exploitable flows, which is positive, but this does not negate the risk presented by the unprotected AJAX endpoint. The plugin has a relatively small attack surface, but the single unprotected entry point is a high-impact vulnerability. Overall, the plugin has strengths in its SQL and escaping but requires immediate attention to secure its AJAX functionality.

Key Concerns

  • Unprotected AJAX handler
  • Missing capability check on AJAX
  • Low percentage of properly escaped output (84%)
Vulnerabilities
None known

Tabs & Pills Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tabs & Pills Release Timeline

v1.5
v1.4
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Tabs & Pills Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
178 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped212 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<class-cdlzr-tabs-metaboxes> (admin/mbox/class-cdlzr-tabs-metaboxes.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Tabs & Pills Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_tabs_wpeditoradmin/class-tabsbox-admin.php:16

Shortcodes 1

[CDLZR_TAB_PILLS] public/class-tabsbox-public.php:8
WordPress Hooks 13
actioninitadmin/class-tabsbox-admin.php:11
actionadmin_menuadmin/class-tabsbox-admin.php:12
actionadd_meta_boxesadmin/class-tabsbox-admin.php:13
actionadmin_initadmin/class-tabsbox-admin.php:14
actionsave_postadmin/class-tabsbox-admin.php:19
actionsave_postadmin/class-tabsbox-admin.php:21
filtermanage_cdlzr_tabs_box_posts_columnsadmin/class-tabsbox-admin.php:23
actionmanage_cdlzr_tabs_box_posts_custom_columnadmin/class-tabsbox-admin.php:24
actionadmin_enqueue_scriptsadmin/mbox/class-cdlzr-tabs-metaboxes.php:9
actionadd_meta_boxesadmin/mbox/class-cdlzr-tabs-metaboxes.php:12
filterwp_enqueue_scriptspublic/class-tabsbox-public.php:9
actionadmin_noticestabs-pills.php:40
actionadmin_inittabs-pills.php:41
Maintenance & Trust

Tabs & Pills Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 24, 2024
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Tabs & Pills Developer Profile

Codelizar

3 plugins · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tabs & Pills

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tabs-pills/admin/assets/js/cdlzr-tabsbox-admin.js/wp-content/plugins/tabs-pills/admin/assets/css/bootstrap.min.css/wp-content/plugins/tabs-pills/admin/assets/css/admin-tabs-css.css/wp-content/plugins/tabs-pills/admin/assets/css/fontawesome/css/all.min.css/wp-content/plugins/tabs-pills/admin/assets/js/custom-js.js/wp-content/plugins/tabs-pills/admin/assets/js/bootstrap.min.js/wp-content/plugins/tabs-pills/admin/assets/css/bootstrap-side-modals.css/wp-content/plugins/tabs-pills/admin/assets/css/jquery-linedtextarea.css+1 more
Script Paths
/wp-content/plugins/tabs-pills/admin/assets/js/cdlzr-tabsbox-admin.js/wp-content/plugins/tabs-pills/admin/assets/js/custom-js.js/wp-content/plugins/tabs-pills/admin/assets/js/bootstrap.min.js/wp-content/plugins/tabs-pills/admin/assets/js/jquery-linedtextarea.js

HTML / DOM Fingerprints

CSS Classes
cdlzr-tabs-box
FAQ

Frequently Asked Questions about Tabs & Pills