
Tea Page Content Security & Risk Analysis
wordpress.org/plugins/tea-page-contentPlugin that allows create widget or shortcode with content of any post, and customize look of blocks via templates.
Is Tea Page Content Safe to Use in 2026?
Generally Safe
Score 85/100Tea Page Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tea-page-content" plugin v1.3.1 exhibits a concerning security posture due to several critical weaknesses, despite a clean vulnerability history. The most significant issue is the presence of 3 AJAX handlers that lack any authentication checks, creating a substantial attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or data manipulation. Furthermore, the plugin uses the `unserialize` function, which is notoriously dangerous and can lead to Remote Code Execution if processing untrusted data. The complete absence of output escaping for all 195 outputs is also a major red flag, making the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. While the plugin uses prepared statements for its SQL queries and has no recorded CVEs, these positive aspects are heavily overshadowed by the identified vulnerabilities in its attack surface and data handling.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Output escaping: 0% properly escaped
- Nonce checks: 0
- Capability checks: 0
Tea Page Content Security Vulnerabilities
Tea Page Content Release Timeline
Tea Page Content Code Analysis
Dangerous Functions Found
Output Escaping
Tea Page Content Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Tea Page Content Maintenance & Trust
Maintenance Signals
Community Trust
Tea Page Content Alternatives
Bloglovin Follow
bloglovin-follow
Allows the user to display their Bloglovin Follow button in posts/pages/ custom post types or in a widget.
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Per Page Sidebars
per-page-sidebars
The Per Page Sidebars (PPS) plugin allows blog administrators to create a unique sidebar for each Page. No template editing is required.
Tea Page Content Developer Profile
1 plugin · 10 total installs
How We Detect Tea Page Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tea-page-content/assets/css/tea-page-content-admin.css/wp-content/plugins/tea-page-content/assets/css/tea-page-content-main.css/wp-content/plugins/tea-page-content/assets/js/tea-page-content-admin.js/wp-content/plugins/tea-page-content/assets/js/tea-page-content-admin-notices.js/wp-content/plugins/tea-page-content/assets/js/tea-page-content-api.js/wp-content/plugins/tea-page-content/assets/js/tea-page-content-api.js/wp-content/plugins/tea-page-content/assets/js/tea-page-content-admin.js/wp-content/plugins/tea-page-content/assets/js/tea-page-content-admin-notices.jstea-page-content/assets/css/tea-page-content-admin.css?ver=tea-page-content/assets/css/tea-page-content-main.css?ver=tea-page-content/assets/js/tea-page-content-admin.js?ver=tea-page-content/assets/js/tea-page-content-admin-notices.js?ver=tea-page-content/assets/js/tea-page-content-api.js?ver=HTML / DOM Fingerprints
data-tpc-widget-id