Ultimate Product Tab Security & Risk Analysis

wordpress.org/plugins/ultimate-product-tab

This plugin will enable an awesome wc ultimate custom product tab.

10 active installs v1.0 PHP + WP 4.3.1+ Updated Nov 27, 2015
custom-tabproduct-tabtabwoocommerce-tab
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Product Tab Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate Product Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "ultimate-product-tab" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities (CVEs) and a lack of dangerous functions suggest a well-maintained codebase. The plugin also correctly utilizes prepared statements for all SQL queries and includes a nonce check for its single AJAX handler, which is a positive indicator for input validation. However, a significant concern lies in the output escaping, with only 54% of outputs being properly escaped. This leaves a substantial portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks. Additionally, the taint analysis revealed one flow with an unsanitized path, which could potentially lead to path traversal or arbitrary file read/write vulnerabilities, although it was not flagged as critical or high severity. The plugin's vulnerability history being completely clear is a good sign, but it doesn't negate the risks identified in the static analysis. In conclusion, while the plugin demonstrates good practices in areas like SQL handling and nonce checks, the insufficient output escaping and the presence of an unsanitized path flow are notable weaknesses that require immediate attention to mitigate potential security risks.

Key Concerns

  • Insufficient output escaping
  • Unsanitized path flow in taint analysis
Vulnerabilities
None known

Ultimate Product Tab Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ultimate Product Tab Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped24 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
save_c_p_tab_field (Ultimate_Custom_Product_Tabs.php:156)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ultimate Product Tab Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_woocommerce_json_custom_tabsUltimate_Custom_Product_Tabs.php:56
WordPress Hooks 8
filterwoocommerce_settings_tabs_arrayUltimate_Custom_Product_Tabs.php:34
actionwoocommerce_product_write_panel_tabsUltimate_Custom_Product_Tabs.php:46
actionwoocommerce_product_write_panelsUltimate_Custom_Product_Tabs.php:48
actionwoocommerce_process_product_metaUltimate_Custom_Product_Tabs.php:50
filterwoocommerce_product_tabsUltimate_Custom_Product_Tabs.php:53
actioninitUltimate_Custom_Product_Tabs.php:58
actionadmin_footerUltimate_Custom_Product_Tabs.php:147
actionadmin_footerUltimate_Custom_Product_Tabs.php:240
Maintenance & Trust

Ultimate Product Tab Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedNov 27, 2015
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Ultimate Product Tab Developer Profile

Md. Shiddikur Rahman

3 plugins · 30 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Product Tab

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-product-tab/assets/css/style.css/wp-content/plugins/ultimate-product-tab/assets/js/scripts.js
Script Paths
/wp-content/plugins/ultimate-product-tab/assets/js/scripts.js
Version Parameters
ultimate-product-tab/assets/css/style.css?ver=ultimate-product-tab/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
custom_product_tabsajax_chosen_select_tabscustom_tab
Data Attributes
data-placeholder
JS Globals
jQuery$
FAQ

Frequently Asked Questions about Ultimate Product Tab