
WP TAB Security & Risk Analysis
wordpress.org/plugins/wp-tabShow any html content in tab to anywhere you want through shortcode
Is WP TAB Safe to Use in 2026?
Generally Safe
Score 85/100WP TAB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-tab plugin v1.0.1 exhibits a mixed security posture. On the positive side, it has a very small attack surface consisting of two shortcodes, and critically, all SQL queries are executed using prepared statements, and there are no dangerous functions, file operations, external HTTP requests, or known historical vulnerabilities. This suggests a developer who is mindful of common web security pitfalls. However, a significant concern arises from the complete lack of output escaping. With 24 total outputs and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. Furthermore, the absence of nonce and capability checks on entry points, although the attack surface is small, leaves these shortcodes potentially vulnerable to CSRF if they perform any sensitive actions. The lack of taint analysis results is also noteworthy; while it could mean no sensitive flows were found, it could also indicate that the analysis was not comprehensive enough to detect subtle vulnerabilities.
In conclusion, while the plugin avoids common pitfalls like unescaped SQL and dangerous functions, the pervasive issue of unescaped output is a critical flaw that significantly undermines its security. The lack of capability and nonce checks on the shortcodes, though not explicitly flagged as critical in the provided data, is another area of potential weakness. Developers should prioritize addressing the output escaping issue to mitigate XSS risks.
Key Concerns
- Unescaped output
- Missing capability checks
- Missing nonce checks
WP TAB Security Vulnerabilities
WP TAB Code Analysis
Output Escaping
WP TAB Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
WP TAB Maintenance & Trust
Maintenance Signals
Community Trust
WP TAB Alternatives
WP Responsive Tabs horizontal vertical and accordion Tabs
responsive-horizontal-vertical-and-accordion-tabs
Create beautiful responsive tabs with a very easy interface. This plugin is all in one tabs plugin means it supports responsive horizontal, vertical a …
Tab – Accordion, FAQ
tabbed
Tab allows you to create a simple tabs, responsive tab, animation tab, horizontal tab, vertical tab, circle tab, FAQ, accordion, animation accordion.
Tabs Responsive – With WooCommerce Product Tabs Extension
tabs-responsive
Tabs Responsive is the most easiest drag & drop Tabs builder for WordPress. You can add unlimited Tabs with unlimited color Scheme.
Tabby Responsive Tabs
tabby-responsive-tabs
Create responsive tabs inside your posts, pages or custom post content by adding simple shortcodes inside the post editor.
Responsive Tabs
responsive-tabs
A responsive & clean way to display your content. Create new tabs in no-time (custom type) and copy-paste the shortcode into any post/page.
WP TAB Developer Profile
3 plugins · 140 total installs
How We Detect WP TAB
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tab/assets/fontAwesome/css/font-awesome.min.css/wp-content/plugins/wp-tab/assets/liquid-slider.css/wp-content/plugins/wp-tab/assets/animate.min.css/wp-content/plugins/wp-tab/assets/jquery.easing.min.js/wp-content/plugins/wp-tab/assets/jquery.touchSwipe.min.js/wp-content/plugins/wp-tab/assets/jquery.liquid-slider.min.js/wp-content/plugins/wp-tab/assets/cf-single-shortcode.jswp-tab-fontAwesomewp-tab-liquidwp-tab-animatewp-tab-easing-jswp-tab-touchSwipe-jswp-tab-liquid-slider-jsHTML / DOM Fingerprints
wp-tab-unique-class-wp-tab-titlewp-tab-contentdata-wp_tab_animate_indata-wp_tab_animate_outdata-wp_tab_animate_durationdata-wp_tab_show_content_titledata-wp_tab_switching_arrowdata-wp_tab_auto_height+7 moreliquidSliderwp_tab_id<div id="wp-tab-id-class="liquid-slider wp-tab-unique-class-<h2 class="title wp-tab-title"><i class="