
Tapz Security & Risk Analysis
wordpress.org/plugins/tapz-inBuild customer relationship through Tapz.
Is Tapz Safe to Use in 2026?
Generally Safe
Score 85/100Tapz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tapz-in" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate a lack of dangerous functions, no raw SQL queries (all are prepared), no file operations, and no external HTTP requests, all of which are positive security indicators. The presence of a capability check is also a good practice. However, the critical concern lies in the complete lack of output escaping for all identified output points. This means any data displayed to users that originates from the plugin could potentially be manipulated to inject malicious content, leading to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Output escaping is not implemented
Tapz Security Vulnerabilities
Tapz Release Timeline
Tapz Code Analysis
Output Escaping
Tapz Attack Surface
WordPress Hooks 4
Maintenance & Trust
Tapz Maintenance & Trust
Maintenance Signals
Community Trust
Tapz Alternatives
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Marker.io – Visual Website Feedback
marker-io
Collect visual website feedback from colleagues and clients on your WordPress site.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Feedbucket – Website Feedback Tool
feedbucket
Enable your clients and team members to submit feedback using screenshot and recordings on your WordPress site.
Banner Upload
banner-upload
Easy way to display the different size of banner advertisements in WordPress using widgets
Tapz Developer Profile
1 plugin · 0 total installs
How We Detect Tapz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tapz-in/tapz_form.phpHTML / DOM Fingerprints
window._tapz_tapz<div id="tapz_widget"></div>