Addons for KingComposer Security & Risk Analysis

wordpress.org/plugins/addons-for-kingcomposer

Impressive modern yet powerful shortcode collections for KingComposer page builder.

200 active installs v1.0.0 PHP + WP 4.0.1+ Updated Apr 19, 2017
addonsking-composer-pluginking-composer-shortcodevc-extensionswordpress-shortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Addons for KingComposer Safe to Use in 2026?

Generally Safe

Score 85/100

Addons for KingComposer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'addons-for-kingcomposer' plugin v1.0.0 exhibits a strong security posture. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests is commendable. The fact that 100% of SQL queries use prepared statements and all outputs are properly escaped indicates good coding practices concerning data handling and presentation. The limited attack surface, with all entry points (shortcodes) implicitly protected by at least one capability check, further enhances its security. The complete lack of known CVEs and past vulnerabilities suggests a history of secure development or a lack of targeted exploitation. However, the complete absence of nonce checks across all entry points is a notable weakness. While capability checks are present, nonce checks are a crucial layer of defense against CSRF attacks, especially for shortcodes which can be triggered by users. The lack of taint analysis results is also a neutral observation; it doesn't indicate good or bad security, but rather a lack of data for this specific analysis.

Key Concerns

  • No nonce checks on entry points
Vulnerabilities
None known

Addons for KingComposer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Addons for KingComposer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Addons for KingComposer Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[akc_before_after] shortcodes\before-after\before-after.php:120
[akc_flipbox] shortcodes\flip-box\flip-box.php:405
[akc_flipbox_3d] shortcodes\flip-box-3d\flip-box-3d.php:381
[akc_hover] shortcodes\hover-effects\hover-effects.php:1703
[akc_infobox] shortcodes\info-box\info-box.php:380
[akc_promobox] shortcodes\promo-box\promo-box.php:237
[akc_servicebox] shortcodes\service-box\service-box.php:510
WordPress Hooks 10
actionadmin_enqueue_scriptsaddons-for-kingcomposer.php:25
actionadmin_initaddons-for-kingcomposer.php:35
actionadmin_noticesaddons-for-kingcomposer.php:38
actioninitshortcodes\before-after\before-after.php:3
actioninitshortcodes\flip-box\flip-box.php:3
actioninitshortcodes\flip-box-3d\flip-box-3d.php:3
actioninitshortcodes\hover-effects\hover-effects.php:3
actioninitshortcodes\info-box\info-box.php:2
actioninitshortcodes\promo-box\promo-box.php:2
actioninitshortcodes\service-box\service-box.php:2
Maintenance & Trust

Addons for KingComposer Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 19, 2017
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Addons for KingComposer Developer Profile

themebon

13 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Addons for KingComposer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addons-for-kingcomposer/admin/admin.css/wp-content/plugins/addons-for-kingcomposer/shortcodes/before-after/css/before-after.css/wp-content/plugins/addons-for-kingcomposer/shortcodes/before-after/js/jquery.event.move.js/wp-content/plugins/addons-for-kingcomposer/shortcodes/before-after/js/jquery.twentytwenty.js

HTML / DOM Fingerprints

CSS Classes
akc_before_after_iconakc_flipbox_icon
Data Attributes
data-kc-shortcode="akc_before_after"data-kc-shortcode="akc_flipbox"
JS Globals
jQuery
Shortcode Output
<div id="container_<img src="<script>jQuery(window).load(function() { jQuery("#container_<div class="flip-box-wrapper
FAQ

Frequently Asked Questions about Addons for KingComposer