
Tides Security & Risk Analysis
wordpress.org/plugins/tidesDo you publish posts about Anime, Film, Animation, Manga, Comics, Games, Literature, Arts, or Writing? Submit to Tides to expand your readership.
Is Tides Safe to Use in 2026?
Generally Safe
Score 85/100Tides has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "tides" v1.0 plugin exhibits a seemingly strong security posture with no identified dangerous functions, external HTTP requests, file operations, or raw SQL queries. The absence of identified vulnerabilities in its history further suggests a low risk profile. However, the analysis reveals critical weaknesses. The plugin's output is entirely unescaped, presenting a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce and capability checks across all entry points, combined with a zero-attack surface in terms of identified AJAX, REST API, shortcodes, and cron events, raises suspicion. It's possible the plugin has no user-facing functionality, or its entry points are not being detected, but the absence of any security checks is a major concern. The vulnerability history showing no prior issues, while positive, does not negate the risks identified in the current code. The lack of proper output escaping is the most immediate and significant threat.
In conclusion, while the "tides" plugin has avoided common pitfalls like raw SQL or dangerous functions, the pervasive lack of output escaping and the absence of any authentication or authorization checks on its (potentially undetected) entry points are serious security flaws. The plugin's strengths lie in its clean code in certain areas, but these are overshadowed by the critical risks related to data sanitization and access control. Until these issues are addressed, the plugin should be considered a moderate to high risk, depending on its actual functionality and intended use.
Key Concerns
- All output is unescaped
- No capability checks found
- No nonce checks found
Tides Security Vulnerabilities
Tides Code Analysis
Output Escaping
Tides Attack Surface
WordPress Hooks 1
Maintenance & Trust
Tides Maintenance & Trust
Maintenance Signals
Community Trust
Tides Alternatives
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Tides Developer Profile
1 plugin · 10 total installs
How We Detect Tides
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
postbox<div class="postbox" style="margin-bottom:0px;margin-top:5px;padding:10px;"><p style="margin:0;">Submit this post to the tides on <a href="http://the-artifice.com">The Artifice</a>. Use <a target="_blank" href="http://the-artifice.com/tides/?ref=">this link</a> with ref code <strong></strong> to boost your post to the top. </p></div>