TCBD Modals Security & Risk Analysis

wordpress.org/plugins/tcbd-modals

This plugin will enable Awesome Modals box in your Wordpress theme.

10 active installs v1.1 PHP + WP 3.0+ Updated Unknown
awesome-modalsbootstrap-modalsmodalsresponsive-modalswordpress-modals
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TCBD Modals Safe to Use in 2026?

Generally Safe

Score 100/100

TCBD Modals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'tcbd-modals' v1.1 plugin exhibits a strong security posture based on the provided static analysis data. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and a lack of output escaping issues are significant strengths. Furthermore, no external HTTP requests or file operations are present, reducing potential attack vectors. The plugin also correctly implements capability checks on its entry points.

While the static analysis reveals no immediate critical risks, the lack of taint analysis data and nonce checks on its single shortcode entry point are minor points of concern. A thorough taint analysis would provide greater confidence in the sanitization of all data flows. The absence of recorded vulnerabilities in its history is positive, suggesting a history of secure development, but it's important to note that this does not guarantee future security.

In conclusion, 'tcbd-modals' v1.1 appears to be a well-developed plugin with a generally good security profile. The presence of capability checks and secure coding practices are commendable. The primary area for potential improvement would be to ensure robust input sanitization and verification for its shortcode, even if current analysis doesn't reveal exploitable flaws.

Key Concerns

  • No nonce checks on entry points
  • No taint analysis data available
Vulnerabilities
None known

TCBD Modals Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TCBD Modals Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE
Attack Surface

TCBD Modals Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tcbd-modals] plugin-hook.php:99
WordPress Hooks 4
filtermce_external_pluginsplugin-hook.php:41
filtermce_buttonsplugin-hook.php:42
actionadmin_headplugin-hook.php:45
actionwp_enqueue_scriptsplugin-hook.php:71
Maintenance & Trust

TCBD Modals Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

TCBD Modals Developer Profile

Touhidul Sadeek

24 plugins · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TCBD Modals

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tcbd-modals/js/tinymce.js/wp-content/plugins/tcbd-modals/js/tcbd-modals.js/wp-content/plugins/tcbd-modals/css/tcbd-modals.css
Script Paths
/wp-content/plugins/tcbd-modals/js/tinymce.js/wp-content/plugins/tcbd-modals/js/tcbd-modals.js
Version Parameters
tcbd-modals/js/tcbd-modals.js?ver=tcbd-modals/css/tcbd-modals.css?ver=

HTML / DOM Fingerprints

CSS Classes
tcbd-modals-titlemodalfademodal-dialogmodal-contentmodal-headermodal-titlemodal-body
Data Attributes
data-toggledata-targetdata-dismissaria-label
Shortcode Output
<span class="tcbd-modals-title" data-toggle="modal"<div class="modal fade"<div class="modal-header"<h4 class="modal-title">
FAQ

Frequently Asked Questions about TCBD Modals