All in One Addons For WPBakery Page Builder (formerly Visual Composer) Security & Risk Analysis

wordpress.org/plugins/all-in-one-visual-composer-addons

Easy solution for building attractive pages with WPBakery Page Builder.

1K active installs v1.2 PHP + WP 3.5+ Updated Oct 21, 2025
image-galleryimage-sliderpricing-tablesteam-showcasewpbakery-addons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All in One Addons For WPBakery Page Builder (formerly Visual Composer) Safe to Use in 2026?

Generally Safe

Score 100/100

All in One Addons For WPBakery Page Builder (formerly Visual Composer) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The 'all-in-one-visual-composer-addons' plugin, version 1.2, presents a mixed security posture. On one hand, the absence of any recorded vulnerabilities (CVEs) and a clean taint analysis suggests that either the plugin has historically been very secure, or it has not been extensively analyzed for complex vulnerabilities. The code analysis also indicates no direct dangerous functions, SQL injection risks via prepared statements, or file operations, which are positive signs. However, a significant concern arises from the complete lack of output escaping. With 819 total outputs analyzed and 0% properly escaped, this creates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-generated or dynamically loaded content that is not meticulously handled before being displayed could be exploited. Additionally, the absence of nonce and capability checks across all entry points, while the entry point count is zero, still points to a potential lack of robust authentication and authorization mechanisms should any entry points exist or be added in future versions.

Key Concerns

  • No properly escaped output detected
  • No nonce checks across entry points
  • No capability checks across entry points
Vulnerabilities
None known

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Release Timeline

v1.2Current
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
819
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped819 total outputs
Attack Surface

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitplugin.class.php:5
actionadmin_enqueue_scriptsplugin.class.php:6
actioninitplugin.class.php:7
actionadmin_noticesplugin.class.php:59
Maintenance & Trust

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 21, 2025
PHP min version
Downloads10K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

All in One Addons For WPBakery Page Builder (formerly Visual Composer) Developer Profile

Labib Ahmed

9 plugins · 8K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
239 days
View full developer profile
Detection Fingerprints

How We Detect All in One Addons For WPBakery Page Builder (formerly Visual Composer)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-visual-composer-addons/assets/css/bootstrap-min.css/wp-content/plugins/all-in-one-visual-composer-addons/assets/css/ult-buttons.css/wp-content/plugins/all-in-one-visual-composer-addons/assets/css/font-awesome.min.css/wp-content/plugins/all-in-one-visual-composer-addons/assets/css/animate.css/wp-content/plugins/all-in-one-visual-composer-addons/assets/js/wow.min.js/wp-content/plugins/all-in-one-visual-composer-addons/assets/js/wdo-custom.js
Script Paths
jquerywdo-wow-js

HTML / DOM Fingerprints

CSS Classes
wdo-ult-containerouter-3dfancy-btnbtn3dwdo-animation-containeranimation-blockwow
Data Attributes
wdo_button_sizewdo_button_stylewdo_button_textwdo_iconwdo_button_linkwdo_target+2 more
JS Globals
ULT_URL
Shortcode Output
<div class="wdo-ult-container"> <div class="outer-3d"> <a id="href="target="class="unique-class-
FAQ

Frequently Asked Questions about All in One Addons For WPBakery Page Builder (formerly Visual Composer)