
Tabs popular posts and latest posts Security & Risk Analysis
wordpress.org/plugins/tabs-widget-popular-posts-and-latest-postsThis is a jquery based lightweight plugin to create a new wordpress tabbed widget to display recent posts and popular posts.
Is Tabs popular posts and latest posts Safe to Use in 2026?
Generally Safe
Score 85/100Tabs popular posts and latest posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tabs-widget-popular-posts-and-latest-posts" plugin v3.9 exhibits a mixed security posture. On the positive side, it has no known historical vulnerabilities (CVEs) and utilizes prepared statements for all SQL queries, which is a strong defense against SQL injection. The static analysis also shows no dangerous function usage, file operations, or external HTTP requests, further reducing common attack vectors.
However, there are significant concerns. The plugin has an "attack surface" consisting of one shortcode, and critically, there are no explicit capability checks or nonce checks evident in the static analysis. This, combined with 29% of output being improperly escaped, suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the shortcode handles user-supplied input. Furthermore, the taint analysis revealed two "flows with unsanitized paths," which, while not rated as critical or high severity in this analysis, warrants investigation as it indicates potential weaknesses in how data is handled, particularly regarding file system interactions or URL manipulation.
In conclusion, while the plugin benefits from a clean vulnerability history and good database security practices, the lack of robust input validation, authorization checks, and output escaping on its entry points presents a notable risk. The "flows with unsanitized paths" are a particular red flag that needs to be addressed to ensure the plugin's security.
Key Concerns
- Unprotected shortcode
- Missing capability checks
- Missing nonce checks
- Improperly escaped output (29%)
- Unsanitized paths in taint flows
Tabs popular posts and latest posts Security Vulnerabilities
Tabs popular posts and latest posts Code Analysis
Output Escaping
Data Flow Analysis
Tabs popular posts and latest posts Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Tabs popular posts and latest posts Maintenance & Trust
Maintenance Signals
Community Trust
Tabs popular posts and latest posts Alternatives
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
WP News and Scrolling Widgets
sp-news-and-widget
A quick, easy way to add an News custom post type, News widget, vertical scrolling news widget to WordPress. Also work with Gutenberg shortcode block.
Lara's Google Analytics (GA4)
lara-google-analytics
Full width Google Analytics dashboard widget for Wordpress admin interface, which also inserts latest Google Analytics (GA4) tracking code to your pag …
Local Google Analytics for WordPress – caches external requests
simple-google-analytics
Plugs in Google Analytics code to your website pages and caches it, so the website loads faster.
Customize Feeds for Twitter
twitter-tweets
Customize Feeds for Twitter plugin for WordPress. You can use this to display real time Twitter feeds on any where on your website by using shortcode …
Tabs popular posts and latest posts Developer Profile
8 plugins · 4K total installs
How We Detect Tabs popular posts and latest posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tabs-widget-popular-posts-and-latest-posts/inc/style.css/wp-content/plugins/tabs-widget-popular-posts-and-latest-posts/inc/script.js/wp-content/plugins/tabs-widget-popular-posts-and-latest-posts/inc/script.js/wp-content/plugins/tabs-widget-popular-posts-and-latest-posts/inc/script.js?ver=1.0HTML / DOM Fingerprints
TabsPostsTabberTabsPostsTabsTabsPostsInsidetplp_popular_titletplp_popular_poststplp_latest_titletplp_latest_poststplp_submit<div id="TabsPostsTabber"><ul class="TabsPostsTabs"><li><a href="#TabsPostsLeft"><li><a href="#TabsPostsRight">