Product Tabs for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-product-tabs

Discover the easy way to add extra tabs to your WooCommerce product pages.

10K active installs v2.1.13 PHP 7.4+ WP 6.1+ Updated Dec 8, 2025
product-tabs-for-woocommercewoocommerce-custom-tabswoocommerce-tab-managerwoocommerce-tabswoocommerce-tabs-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Tabs for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Product Tabs for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "woocommerce-product-tabs" v2.1.13 plugin exhibits a generally strong security posture with no recorded vulnerabilities or critical taint flows. The absence of dangerous functions, external HTTP requests, and file operations is commendable. The plugin also incorporates a reasonable number of nonce and capability checks, indicating an awareness of common security practices.

However, there are areas for improvement. A significant concern is the low percentage of properly escaped output (6%). This could expose the plugin to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed. While the taint analysis shows no unsanitized paths, the low output escaping rate is a red flag that warrants investigation. The presence of 80% prepared statements for SQL queries is good, but the remaining 20% could still pose a risk if not carefully managed.

Overall, the plugin appears to be relatively secure due to its lack of known vulnerabilities and a limited attack surface. Nevertheless, the low output escaping rate represents a notable weakness that could be exploited. Addressing this would significantly improve its security.

Key Concerns

  • Low percentage of properly escaped output
  • SQL queries without prepared statements (20%)
Vulnerabilities
None known

Product Tabs for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Tabs for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
12 prepared
Unescaped Output
187
11 escaped
Nonce Checks
5
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared15 total queries

Output Escaping

6% escaped198 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_tab_priority (src\Admin\Single_Tab.php:198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product Tabs for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
filterplugin_row_metasrc\Admin\Admin_Controller.php:40
actionadmin_enqueue_scriptssrc\Admin\Admin_Controller.php:43
filterwoocommerce_product_data_tabssrc\Admin\Product_Editor_Tabs.php:31
actionwoocommerce_product_data_panelssrc\Admin\Product_Editor_Tabs.php:32
actionsave_postsrc\Admin\Product_Editor_Tabs.php:33
filterwp_insert_post_datasrc\Admin\Product_Editor_Tabs.php:34
actionadmin_headsrc\Admin\Product_Editor_Tabs.php:35
actionsave_post_productsrc\Admin\Product_Editor_Tabs.php:36
actionadmin_initsrc\Admin\Product_Editor_Tabs.php:37
actionadmin_noticessrc\Admin\Product_Editor_Tabs.php:38
actionsave_postsrc\Admin\Product_Editor_Tabs.php:39
actionsave_postsrc\Admin\Product_Editor_Tabs.php:157
actionadmin_noticessrc\Admin\Product_Editor_Tabs.php:310
filterin_admin_headersrc\Admin\Settings_Page.php:57
actionadmin_menusrc\Admin\Settings_Page.php:58
actionadmin_initsrc\Admin\Settings_Page.php:59
filterbarn2_plugin_settings_help_linkssrc\Admin\Settings_Page.php:60
actionadd_meta_boxessrc\Admin\Single_Tab.php:20
actionsave_postsrc\Admin\Single_Tab.php:21
actionsave_postsrc\Admin\Single_Tab.php:22
actionsave_postsrc\Admin\Single_Tab.php:23
actionafter_setup_themesrc\Plugin.php:58
actionadmin_initsrc\Plugin_Setup.php:59
actioninitsrc\Post_Type.php:19
actionadmin_head-post.phpsrc\Post_Type.php:20
actionadmin_head-post-new.phpsrc\Post_Type.php:21
filtermanage_woo_product_tab_posts_columnssrc\Post_Type.php:22
actionmanage_woo_product_tab_posts_custom_columnsrc\Post_Type.php:23
filterpost_updated_messagessrc\Post_Type.php:24
filterpost_row_actionssrc\Post_Type.php:25
filtermanage_edit-woo_product_tab_sortable_columnssrc\Post_Type.php:26
filterparent_filesrc\Post_Type.php:27
filtercustom_menu_ordersrc\Post_Type.php:28
filtermenu_ordersrc\Post_Type.php:29
filteruse_block_editor_for_post_typesrc\Post_Type.php:30
filterwoocommerce_product_tabssrc\Product_Tabs.php:23
filterwc_quick_view_pro_quick_view_tabs_enabledsrc\Product_Tabs.php:24
filterwpt_filter_product_tabssrc\Product_Tabs.php:26
filterwpt_use_the_content_filtersrc\Product_Tabs.php:29
filterwpt_filter_tab_contentsrc\Product_Tabs.php:30
Maintenance & Trust

Product Tabs for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.4
Downloads250K

Community Trust

Rating94/100
Number of ratings70
Active installs10K
Developer Profile

Product Tabs for WooCommerce Developer Profile

Barn2 Plugins

5 plugins · 21K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Product Tabs for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-product-tabs/assets/css/frontend.css/wp-content/plugins/woocommerce-product-tabs/assets/css/product-tabs.css/wp-content/plugins/woocommerce-product-tabs/assets/js/frontend.js
Script Paths
/wp-content/plugins/woocommerce-product-tabs/assets/js/frontend.js
Version Parameters
/wp-content/plugins/woocommerce-product-tabs/assets/css/frontend.css?ver=/wp-content/plugins/woocommerce-product-tabs/assets/css/product-tabs.css?ver=/wp-content/plugins/woocommerce-product-tabs/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
b2-product-tabsb2-tab-item
Data Attributes
data-tab-iddata-tab-title
FAQ

Frequently Asked Questions about Product Tabs for WooCommerce