Tabsy Security & Risk Analysis

wordpress.org/plugins/tabsy

Tabsy is a free smart responsive WordPress tabs plugin that is designed to fit on every container width beautifully.

200 active installs v1.4 PHP + WP 3.8+ Updated Dec 11, 2016
jquery-tabsresponsiveresponsive-tabssmart-responsivewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tabsy Safe to Use in 2026?

Generally Safe

Score 85/100

Tabsy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin "tabsy" v1.4 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-total and zero-unprotected attack surface. Furthermore, the code signals are highly positive: no dangerous functions are used, all SQL queries are prepared, and output is properly escaped. The absence of file operations, external HTTP requests, and crucially, a lack of nonce and capability checks on any entry points, points to a potentially overly simplistic approach that hasn't yet encountered exploitable code paths.

The vulnerability history is also clean, with no known CVEs recorded for this plugin. This lack of past vulnerabilities, combined with the stringent application of secure coding practices in the static analysis, suggests the developers have been diligent in their security efforts or that the plugin's limited functionality hasn't attracted significant scrutiny or attack attempts. However, the complete absence of capability checks and nonce checks, while currently resulting in a zero attack surface, could become a concern if the plugin's functionality were to expand in the future without the corresponding introduction of these essential security measures.

In conclusion, "tabsy" v1.4 appears to be a highly secure plugin at this version, demonstrating excellent adherence to secure coding principles and a clean vulnerability history. The primary, albeit theoretical, concern lies in the complete absence of capability and nonce checks, which, while not currently posing a risk due to the limited attack surface, represents a potential future risk if the plugin's scope increases. The lack of any recorded vulnerabilities is a significant strength.

Vulnerabilities
None known

Tabsy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tabsy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Tabsy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptscore\functions.enqueue.php:26
actioninitcore\functions.shortcode.php:23
filterwptabsy_shortcodecore\functions.shortcode.php:24
filterwidget_textwp-tabsy.php:22
Maintenance & Trust

Tabsy Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 11, 2016
PHP min version
Downloads15K

Community Trust

Rating88/100
Number of ratings7
Active installs200
Developer Profile

Tabsy Developer Profile

Jeffrey Carandang

7 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tabsy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tabsy/assets/css/tabsy.css/wp-content/plugins/tabsy/assets/font-awesome-4.3.0/css/font-awesome.min.css/wp-content/plugins/tabsy/assets/js/jquery.tabsy.js/wp-content/plugins/tabsy/assets/js/wptabsy.js
Script Paths
/wp-content/plugins/tabsy/assets/js/jquery.tabsy.js/wp-content/plugins/tabsy/assets/js/wptabsy.js

HTML / DOM Fingerprints

CSS Classes
wptabsywptabsy-navwptabsy-innerwptabsy-contentwptabsy-skin-
Data Attributes
data-
JS Globals
jQuery.tabsy
Shortcode Output
<div class="wptabsy<ul class="wptabsy-nav"><div class="wptabsy-inner"><div class="wptabsy-content"
FAQ

Frequently Asked Questions about Tabsy