TailPress – Tailwind for WordPress Security & Risk Analysis

wordpress.org/plugins/tailpress

Seamless integration of Tailwind for WordPress.

600 active installs v0.4.4 PHP 7.0+ WP 5.2+ Updated Apr 4, 2023
blockscssgutenbergtailwindutility-classes
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 3, 2025
Safety Verdict

Is TailPress – Tailwind for WordPress Safe to Use in 2026?

Use With Caution

Score 64/100

TailPress – Tailwind for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 3, 2025Updated 3yr ago
Risk Assessment

The TailPress plugin v0.4.4 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and avoiding external HTTP requests, several concerning areas require attention. The static analysis reveals a significant attack surface with two AJAX handlers, one of which lacks proper authentication checks. This unprotected entry point is a primary concern, as it could potentially be exploited by unauthorized actors to perform unintended actions or gain access to sensitive information. Furthermore, the plugin's output escaping is only 33% properly handled, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities where user-controlled data might be rendered without adequate sanitization. The vulnerability history, specifically a medium-severity CVE related to 'Exposure of Sensitive Information to an Unauthorized Actor,' reinforces these concerns. The presence of an unpatched medium-severity vulnerability, even with a future date, indicates a known security flaw that could be exploited if it were active. The combination of an unprotected AJAX handler, insufficient output escaping, and a history of information exposure vulnerabilities indicates a need for immediate review and remediation.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Unpatched medium CVE
  • Missing capability checks on AJAX
Vulnerabilities
1 published

TailPress – Tailwind for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31558medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

TailPress <= 0.4.4 - Unauthenticated Sensitive Information Exposure

Apr 3, 2025Unpatched
Version History

TailPress – Tailwind for WordPress Release Timeline

v0.4.4Current1 CVE
v0.4.31 CVE
v0.4.21 CVE
v0.4.11 CVE
v0.4.01 CVE
v0.3.21 CVE
v0.3.11 CVE
v0.3.01 CVE
v0.2.01 CVE
v0.1.21 CVE
v0.1.11 CVE
v0.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

TailPress – Tailwind for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped15 total outputs
Attack Surface
1 unprotected

TailPress – Tailwind for WordPress Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_tailpress_ajax_clear_cachesrc\Admin.php:27
noprivwp_ajax_tailpress_ajaxsrc\Plugin.php:78
WordPress Hooks 8
actionwp_headsrc\Frontend.php:29
actiontemplate_redirectsrc\Plugin.php:52
actionshutdownsrc\Plugin.php:61
actionwp_enqueue_scriptssrc\Plugin.php:77
actionadmin_enqueue_scriptssrc\Plugin.php:88
actionadmin_menusrc\Plugin.php:89
actionadmin_initsrc\Plugin.php:90
actionupdate_option_tailpress_plugin_optionssrc\Settings.php:34
Maintenance & Trust

TailPress – Tailwind for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 4, 2023
PHP min version7.0
Downloads14K

Community Trust

Rating100/100
Number of ratings13
Active installs600
Developer Profile

TailPress – Tailwind for WordPress Developer Profile

Greg

4 plugins · 630 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TailPress – Tailwind for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tailpress/js/twind.cdn.1.0.5.js/wp-content/plugins/tailpress/js/twind.cdn.1.0.8.js/wp-content/plugins/tailpress/js/vendor/json-editor.0.2.4.js/wp-content/plugins/tailpress/js/clear-cache.js
Script Paths
/wp-content/plugins/tailpress/js/twind.cdn.1.0.5.js/wp-content/plugins/tailpress/js/twind.cdn.1.0.8.js/wp-content/plugins/tailpress/js/vendor/json-editor.0.2.4.js/wp-content/plugins/tailpress/js/clear-cache.js
Version Parameters
tailpress/style.css?ver=tailpress-json-editor?ver=tailpress-clear-cache.js?ver=tailpress_twind_admin?ver=tailpress_twind?ver=

HTML / DOM Fingerprints

JS Globals
twind.install
FAQ

Frequently Asked Questions about TailPress – Tailwind for WordPress