Ace Post Type Builder Security & Risk Analysis

wordpress.org/plugins/ace-post-type-builder

Post Type Builder: Simplifies creating and managing custom post types in WordPress with an intuitive interface and compatibility with page builders.

300 active installs v2.1 PHP 7.2+ WP 5.2+ Updated Jan 19, 2026
advanced-field-managementcustom-post-typestaxonomy-support
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 24, 2025
Download
Safety Verdict

Is Ace Post Type Builder Safe to Use in 2026?

Generally Safe

Score 99/100

Ace Post Type Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 24, 2025Updated 3mo ago
Risk Assessment

The "ace-post-type-builder" plugin v2.1 exhibits a generally good security posture, with a strong emphasis on secure coding practices. The static analysis reveals no dangerous functions, all SQL queries are prepared, and output escaping is consistently high at 94%. The absence of file operations and the limited number of external HTTP requests are also positive indicators. Furthermore, the plugin implements a commendable number of nonce and capability checks, contributing to a robust defense against common web attacks. The attack surface, while present with three AJAX handlers, is entirely protected by authorization checks, and the lack of REST API routes or shortcodes further limits potential entry points.

However, the plugin is not without its concerns. The single known CVE in its history, even though currently patched, indicates a past vulnerability. While the specific type is not detailed beyond "Missing Authorization", it warrants attention as it suggests that authorization mechanisms, despite their current implementation, have been a point of past weakness. The taint analysis showing zero flows is a positive, but this could be due to the limited scope of analysis or the nature of the code. The plugin's vulnerability history, despite the current lack of unpatched CVEs, suggests that a proactive approach to security and ongoing vigilance are essential.

In conclusion, "ace-post-type-builder" v2.1 demonstrates many positive security attributes, making it relatively secure. The developers have clearly invested in secure coding practices. The primary area of concern remains the past vulnerability, which, although resolved, serves as a reminder of potential risks. Continued monitoring and timely updates for any future security advisories are recommended to maintain its strong security standing.

Key Concerns

  • Past vulnerability (Missing Authorization)
Vulnerabilities
1 published

Ace Post Type Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-13405medium · 5.3Missing Authorization

Ace Post Type Builder <= 1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Custom Taxonomy Deletion via 'taxonomy' Parameter

Nov 24, 2025 Patched in 2.0 (15d)
Version History

Ace Post Type Builder Release Timeline

v2.1Current
v2.0
v1.91 CVE
v1.81 CVE
v1.71 CVE
v1.61 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Ace Post Type Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
126 escaped
Nonce Checks
8
Capability Checks
7
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped134 total outputs
Attack Surface

Ace Post Type Builder Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_cptb_get_filtered_productsglobal-functions.php:139
noprivwp_ajax_cptb_get_filtered_productsglobal-functions.php:140
authwp_ajax_cptb_dismiss_noticeglobal-functions.php:144
WordPress Hooks 15
actionplugins_loadedace-post-type-builder.php:51
actionadmin_noticesace-post-type-builder.php:53
actioninitincludes\class-cptb-core.php:23
actioninitincludes\class-cptb-core.php:24
actionadmin_enqueue_scriptsincludes\class-cptb-core.php:25
actionadmin_menuincludes\class-cptb-core.php:26
actionadmin_post_cptb_save_post_typeincludes\class-cptb-core.php:27
actionadmin_post_cptb_save_taxonomyincludes\class-cptb-core.php:28
actionelementor/initincludes\class-cptb-core.php:29
actionadmin_post_cptb_delete_post_typeincludes\class-cptb-core.php:30
actionadmin_post_cptb_delete_taxonomyincludes\class-cptb-core.php:31
actionadmin_post_cptb_update_taxonomyincludes\class-cptb-core.php:32
actionadmin_post_cptb_update_post_typeincludes\class-cptb-core.php:33
actionadmin_headincludes\class-cptb-core.php:35
filterelementor/query/get_query_argsincludes\class-cptb-core.php:120
Maintenance & Trust

Ace Post Type Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version7.2
Downloads7K

Community Trust

Rating20/100
Number of ratings1
Active installs300
Developer Profile

Ace Post Type Builder Developer Profile

Buywptemplates

43 plugins · 5K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Ace Post Type Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ace-post-type-builder/assets/css/cptb-admin.css/wp-content/plugins/ace-post-type-builder/assets/js/cptb-admin.js/wp-content/plugins/ace-post-type-builder/assets/js/ace-editor.min.js/wp-content/plugins/ace-post-type-builder/assets/js/cptb-frontend.js
Script Paths
/wp-content/plugins/ace-post-type-builder/assets/js/cptb-admin.js/wp-content/plugins/ace-post-type-builder/assets/js/ace-editor.min.js/wp-content/plugins/ace-post-type-builder/assets/js/cptb-frontend.js
Version Parameters
ace-post-type-builder/assets/css/cptb-admin.css?ver=ace-post-type-builder/assets/js/cptb-admin.js?ver=ace-post-type-builder/assets/js/ace-editor.min.js?ver=ace-post-type-builder/assets/js/cptb-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
cptbcptb-notice-banner-wrapcptb-notice-banner-leftcptb-per-wrapcptb-imgcptb-notice-banner-rightcptb-notice-banner-content-wrapcptb-banner-heading+4 more
Data Attributes
data-cptb-nonce
JS Globals
CPTB_PLUGIN_URLcptb_data
FAQ

Frequently Asked Questions about Ace Post Type Builder