Wp Taxonomy Tab Security & Risk Analysis

wordpress.org/plugins/wp-taxonomy-tab

This is taxonomy tab post plugin. It has admin controls options. It is a Responsive WordPress Terms Tab Plugin, to view terms and its posts inside ta …

10 active installs v1.0 PHP + WP + Updated May 4, 2019
category-tabresponsive-tabtabtab-posttaxonomy-tab
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Wp Taxonomy Tab Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Taxonomy Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The wp-taxonomy-tab v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by completely avoiding dangerous functions, performing all SQL queries using prepared statements, and not making external HTTP requests or file operations. The absence of any recorded vulnerabilities, critical or otherwise, in its history is also a strong indicator of diligent development and testing. However, significant concerns arise from the static analysis. The plugin has an unprotected AJAX handler, which represents a direct entry point for potential attacks without any authentication or authorization checks. Furthermore, the low percentage of properly escaped output (22%) is a critical weakness, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across various output points. The lack of capability checks on its entry points further compounds the risk, as any user, regardless of their role, could potentially trigger unintended actions or expose sensitive information.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

Wp Taxonomy Tab Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wp Taxonomy Tab Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped58 total outputs
Attack Surface
1 unprotected

Wp Taxonomy Tab Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_taxonomiesResultinit.php:203

Shortcodes 1

[WptTabpost] init.php:226
WordPress Hooks 7
actionadmin_enqueue_scriptsinit.php:31
actionwp_enqueue_scriptsinit.php:42
actionwp_footerinit.php:49
filterexcerpt_moreinit.php:56
actioninitinit.php:59
actionadd_meta_boxesinit.php:68
actionsave_postinit.php:172
Maintenance & Trust

Wp Taxonomy Tab Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 4, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wp Taxonomy Tab Developer Profile

Anandaraj Balu

3 plugins · 110 total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Wp Taxonomy Tab

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-taxonomy-tab/wpt-style.css/wp-content/plugins/wp-taxonomy-tab/admin/css/style.css/wp-content/plugins/wp-taxonomy-tab/admin/js/custom.js/wp-content/plugins/wp-taxonomy-tab/wpt-tab.js
Version Parameters
wp-taxonomy-tab/wpt-style.css?ver=wp-taxonomy-tab/admin/css/style.css?ver=wp-taxonomy-tab/admin/js/custom.js?ver=wp-taxonomy-tab/wpt-tab.js?ver=

HTML / DOM Fingerprints

CSS Classes
TabSelectTabOptiontitle-tabspost-typesWpTabTaxonomypost-taxonomytab-inputcolor-field
Data Attributes
Onchange="Wptabs_ShowTaxo(this.value);"onchange="Wptabs_ShowTerms(this.value);"
FAQ

Frequently Asked Questions about Wp Taxonomy Tab