TailPress – Tailwind for WordPress Security & Risk Analysis

wordpress.org/plugins/tailpress

Seamless integration of Tailwind for WordPress.

600 active installs v0.4.4 PHP 7.0+ WP 5.2+ Updated Apr 4, 2023
blockscssgutenbergtailwindutility-classes
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 3, 2025
Safety Verdict

Is TailPress – Tailwind for WordPress Safe to Use in 2026?

Use With Caution

Score 64/100

TailPress – Tailwind for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 3, 2025Updated 3yr ago
Risk Assessment

The TailPress plugin v0.4.4 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and avoiding external HTTP requests, several concerning areas require attention. The static analysis reveals a significant attack surface with two AJAX handlers, one of which lacks proper authentication checks. This unprotected entry point is a primary concern, as it could potentially be exploited by unauthorized actors to perform unintended actions or gain access to sensitive information. Furthermore, the plugin's output escaping is only 33% properly handled, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities where user-controlled data might be rendered without adequate sanitization. The vulnerability history, specifically a medium-severity CVE related to 'Exposure of Sensitive Information to an Unauthorized Actor,' reinforces these concerns. The presence of an unpatched medium-severity vulnerability, even with a future date, indicates a known security flaw that could be exploited if it were active. The combination of an unprotected AJAX handler, insufficient output escaping, and a history of information exposure vulnerabilities indicates a need for immediate review and remediation.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Unpatched medium CVE
  • Missing capability checks on AJAX
Vulnerabilities
1

TailPress – Tailwind for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31558medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

TailPress <= 0.4.4 - Unauthenticated Sensitive Information Exposure

Apr 3, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

TailPress – Tailwind for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped15 total outputs
Attack Surface
1 unprotected

TailPress – Tailwind for WordPress Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_tailpress_ajax_clear_cachesrc\Admin.php:27
noprivwp_ajax_tailpress_ajaxsrc\Plugin.php:78
WordPress Hooks 8
actionwp_headsrc\Frontend.php:29
actiontemplate_redirectsrc\Plugin.php:52
actionshutdownsrc\Plugin.php:61
actionwp_enqueue_scriptssrc\Plugin.php:77
actionadmin_enqueue_scriptssrc\Plugin.php:88
actionadmin_menusrc\Plugin.php:89
actionadmin_initsrc\Plugin.php:90
actionupdate_option_tailpress_plugin_optionssrc\Settings.php:34
Maintenance & Trust

TailPress – Tailwind for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 4, 2023
PHP min version7.0
Downloads14K

Community Trust

Rating100/100
Number of ratings13
Active installs600
Developer Profile

TailPress – Tailwind for WordPress Developer Profile

Greg

3 plugins · 630 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TailPress – Tailwind for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tailpress/js/twind.cdn.1.0.5.js/wp-content/plugins/tailpress/js/twind.cdn.1.0.8.js/wp-content/plugins/tailpress/js/vendor/json-editor.0.2.4.js/wp-content/plugins/tailpress/js/clear-cache.js
Script Paths
/wp-content/plugins/tailpress/js/twind.cdn.1.0.5.js/wp-content/plugins/tailpress/js/twind.cdn.1.0.8.js/wp-content/plugins/tailpress/js/vendor/json-editor.0.2.4.js/wp-content/plugins/tailpress/js/clear-cache.js
Version Parameters
tailpress/style.css?ver=tailpress-json-editor?ver=tailpress-clear-cache.js?ver=tailpress_twind_admin?ver=tailpress_twind?ver=

HTML / DOM Fingerprints

JS Globals
twind.install
FAQ

Frequently Asked Questions about TailPress – Tailwind for WordPress