WindPress – Tailwind CSS integration for WordPress Security & Risk Analysis

wordpress.org/plugins/windpress

Integrate Tailwind CSS 3 or 4 into WordPress easily, in seconds. Works well with the block editor, page builders, plugins, themes, and custom code.

3K active installs v3.2.76 PHP 7.4+ WP 6.0+ Updated Feb 28, 2026
blocktailwindtailwind-csstailwindcss
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WindPress – Tailwind CSS integration for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

WindPress – Tailwind CSS integration for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "windpress" v3.2.76 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces its attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, all SQL queries employing prepared statements, and a high percentage of output properly escaped. The presence of numerous capability checks and a reasonable number of nonce checks further indicates a developer's awareness of security. The plugin also boasts a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or a lack of past exploitation. However, the analysis does reveal a moderate number of file operations (8), which, while not inherently insecure, represent potential areas for concern if not implemented with strict path validation and sanitization. The 12% of output that is not properly escaped, though not quantified by severity, could still lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled and displayed without further sanitization. Despite these minor points of caution, the overall security of "windpress" v3.2.76 appears robust.

Key Concerns

  • Unescaped output detected
  • File operations present
Vulnerabilities
None known

WindPress – Tailwind CSS integration for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WindPress – Tailwind CSS integration for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
22 escaped
Nonce Checks
2
Capability Checks
13
File Operations
8
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped25 total outputs
Attack Surface

WindPress – Tailwind CSS integration for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 46
actionwp_abilities_api_categories_initsrc\Abilities\Loader.php:79
actionwp_abilities_api_initsrc\Abilities\Loader.php:81
actionadmin_menusrc\Admin\AdminPage.php:21
filterf!windpress/core/runtime:print_windpress_metadatasrc\Admin\AdminPage.php:49
actionadmin_enqueue_scriptssrc\Admin\AdminPage.php:50
actionadmin_enqueue_scriptssrc\Admin\AdminPage.php:51
actionrest_api_initsrc\Api\Router.php:28
actionwp_headsrc\Core\Runtime.php:88
actionwp_headsrc\Core\Runtime.php:92
actionwp_headsrc\Core\Runtime.php:94
actionwp_headsrc\Core\Runtime.php:97
actionwp_headsrc\Core\Runtime.php:99
actionwp_headsrc\Core\Runtime.php:102
filtersanitize_file_name_charssrc\Core\Volume.php:109
filterf!windpress/core/cache:compile.providerssrc\Integration\Elementor\Main.php:24
filterf!windpress/core/runtime:append_header.exclude_adminsrc\Integration\Elementor\Main.php:26
filterf!windpress/core/cache:compile.providerssrc\Integration\GreenShift\Main.php:25
actioninitsrc\Integration\Gutenberg\CommonBlock.php:41
filterblock_default_classnamesrc\Integration\Gutenberg\CommonBlock.php:42
filterf!windpress/core/runtime:enqueue_play_modules.loaded_modulessrc\Integration\Gutenberg\CommonBlock.php:43
actionenqueue_block_editor_assetssrc\Integration\Gutenberg\Editor.php:28
filterwp_theme_json_data_themesrc\Integration\Gutenberg\Editor.php:30
filterwp_theme_json_data_usersrc\Integration\Gutenberg\Editor.php:31
actionadmin_headsrc\Integration\Gutenberg\Editor.php:38
filterf!windpress/core/cache:compile.providerssrc\Integration\Gutenberg\Main.php:24
filterf!windpress/core/cache:compile.providerssrc\Integration\Kadence\Main.php:25
actionlc_editor_before_body_closingsrc\Integration\LiveCanvas\Editor.php:24
filterf!windpress/core/cache:compile.providerssrc\Integration\LiveCanvas\Main.php:24
filterf!windpress/core/runtime:is_prevent_loadsrc\Integration\LiveCanvas\Main.php:26
filterf!windpress/core/runtime:append_header.exclude_adminsrc\Integration\LiveCanvas\Main.php:27
filterf!windpress/core/cache:compile.providerssrc\Integration\Timber\Main.php:24
actionupgrader_process_completesrc\Plugin.php:92
actionplugins_loadedsrc\Plugin.php:102
actioninitsrc\Plugin.php:103
actionadmin_noticessrc\Plugin.php:162
filterscript_loader_tagsrc\Utils\AssetVite.php:171
filterwp_inline_script_attributessrc\Utils\AssetVite.php:251
actionwp_print_scriptssrc\Utils\Cache.php:92
filtersgo_js_minify_excludesrc\Utils\Cache.php:107
filtersgo_javascript_combine_excludesrc\Utils\Cache.php:108
filtersgo_js_async_excludesrc\Utils\Cache.php:109
filterrocket_exclude_async_csssrc\Utils\Cache.php:137
filterrocket_delay_js_exclusionssrc\Utils\Cache.php:143
filterrocket_exclude_defer_jssrc\Utils\Cache.php:149
filterrocket_defer_inline_exclusionssrc\Utils\Cache.php:155
filterrocket_excluded_inline_js_contentsrc\Utils\Cache.php:158
Maintenance & Trust

WindPress – Tailwind CSS integration for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version7.4
Downloads46K

Community Trust

Rating100/100
Number of ratings34
Active installs3K
Developer Profile

WindPress – Tailwind CSS integration for WordPress Developer Profile

Sua

3 plugins · 8K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WindPress – Tailwind CSS integration for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/windpress/assets/wp-i18n.js/wp-content/plugins/windpress/build/assets/dashboard/main.ts
Script Paths
/wp-content/plugins/windpress/build/assets/dashboard/main.ts/wp-content/plugins/windpress/assets/wp-i18n.js
Version Parameters
/wp-content/plugins/windpress/build/assets/dashboard/main.ts?ver=/wp-content/plugins/windpress/assets/wp-i18n.js?ver=

HTML / DOM Fingerprints

CSS Classes
windpress-app
JS Globals
WIND_PRESS
FAQ

Frequently Asked Questions about WindPress – Tailwind CSS integration for WordPress