
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Security & Risk Analysis
wordpress.org/plugins/wp-expand-tabs-freeA customizable plugin to create and manage WooCommerce product tabs and WordPress tabs to organize content.
Is Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Safe to Use in 2026?
Generally Safe
Score 96/100Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wp-expand-tabs-free" plugin v3.1.3 presents a mixed security posture. While it demonstrates strengths in using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain regarding its attack surface and past vulnerability history. The presence of 3 AJAX handlers without authentication checks exposes potential entry points for unauthorized actions, especially when combined with the use of the dangerous `unserialize` function, which has historically been a vector for deserialization vulnerabilities. The plugin also has a notable history of 5 CVEs, including a high-severity vulnerability in the past, and common types such as deserialization, XSS, and CSRF, indicating recurring security weaknesses. While there are no currently unpatched CVEs and no critical taint flows identified in this specific static analysis, the past vulnerability patterns and the identified unprotected AJAX handlers warrant caution.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- High severity CVE in history
- Multiple past CVEs
- Common vulnerability types: Deserialization, XSS, CSRF
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Tabs <= 2.2.12 - Authenticated (Administrator+) PHP Object Injection
WP Tabs <= 2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Tabs <= 2.1.14 - Cross Site Request Forgery
WP Tabs <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP Tabs – Responsive Tabs Plugin for WordPress <= 1.8.0 - Stored Cross-Site Scripting
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Release Timeline
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 82
Maintenance & Trust
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Maintenance & Trust
Maintenance Signals
Community Trust
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Alternatives
Custom Product tabs for WooCommerce
wb-custom-product-tabs-for-woocommerce
Create unlimited WooCommerce tabs and assign them in bulk by category, tag, brand, or product. Also disable WooCommerce’s default product tabs.
Product Tabs for WooCommerce
woocommerce-product-tabs
Discover the easy way to add extra tabs to your WooCommerce product pages.
TG Product Tab Manager
product-tab-manager
This plugin allows you to manage your Woocommerce product page tabs. Tabs can be renamed, removed and re-ordered on the single product page.
Product Tabs Manager – Custom WooCommerce Product Tabs, Extra Tabs, Tab Editor & Tab Customizer
product-tabs-manager
Create unlimited custom WooCommerce product tabs, manage default tabs, exclude tabs by product or category, add specifications, FAQs & more – 100% …
Dynamic Product Tabs Builder for WooCommerce
dynamic-product-tabs-builder-for-woocommerce
Create custom product tabs with custom content for clearer WooCommerce product pages - Defined sitewide or per product.
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs Developer Profile
18 plugins · 315K total installs
How We Detect Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-expand-tabs-free/public/assets/css/sp-wp-tabs-free.min.css/wp-content/plugins/wp-expand-tabs-free/public/assets/js/sp-wp-tabs-free.min.js/wp-content/plugins/wp-expand-tabs-free/public/assets/css/font-awesome.min.css/wp-content/plugins/wp-expand-tabs-free/admin/css/wp-tabs-admin.min.css/wp-content/plugins/wp-expand-tabs-free/public/assets/js/sp-wp-tabs-free.min.jswp-expand-tabs-free/public/assets/css/sp-wp-tabs-free.min.css?ver=wp-expand-tabs-free/public/assets/js/sp-wp-tabs-free.min.js?ver=wp-expand-tabs-free/public/assets/css/font-awesome.min.css?ver=wp-expand-tabs-free/admin/css/wp-tabs-admin.min.css?ver=HTML / DOM Fingerprints
sp-wp-tabs-free-container<!-- SP Tabs Free Widget -->data-sp-tabs-free-idsp_wp_tabs_free_params[sp_wp_tabs id=""]