Essential Doo Components for Visual Composer Security & Risk Analysis

wordpress.org/plugins/animated-icon-banner-for-visual-composer

Essential Doo Components is the original addon built for Visual Composer which helps you add interactive overlay effects on the sections displayed on …

400 active installs v1.9 PHP + WP 3.0.1+ Updated Jun 23, 2015
bannercarouselvisual-composer
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 18, 2025
Download
Safety Verdict

Is Essential Doo Components for Visual Composer Safe to Use in 2026?

Use With Caution

Score 63/100

Essential Doo Components for Visual Composer has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 18, 2025Updated 10yr ago
Risk Assessment

The plugin 'animated-icon-banner-for-visual-composer' v1.9 presents a mixed security profile. On one hand, the static analysis shows commendable practices regarding SQL query sanitization and output escaping, with 100% of analyzed outputs being properly escaped and all SQL queries utilizing prepared statements. The plugin also lacks external HTTP requests and file operations, which generally reduces its attack surface.

However, significant concerns arise from the vulnerability history. The presence of one unpatched medium severity vulnerability, specifically Cross-Site Scripting (XSS), dating from August 18, 2025, is a major red flag. The lack of any nonce checks or capability checks across all entry points (shortcodes in this case) further amplifies the risk associated with the known XSS vulnerability, as unauthorized or less privileged users could potentially exploit it if not properly mitigated by the WordPress core or theme.

In conclusion, while the code exhibits good practices in specific areas like data sanitization, the unpatched XSS vulnerability and the absence of robust authentication checks on its shortcodes are critical weaknesses. Users are strongly advised to update the plugin to a patched version if available, or to exercise extreme caution and consider disabling it until the vulnerability is addressed.

Key Concerns

  • Unpatched medium severity CVE (XSS)
  • No nonce checks on shortcodes
  • No capability checks on shortcodes
Vulnerabilities
1 published

Essential Doo Components for Visual Composer Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49424medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Essential Doo Components for Visual Composer <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 18, 2025Unpatched
Version History

Essential Doo Components for Visual Composer Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Essential Doo Components for Visual Composer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Essential Doo Components for Visual Composer Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[vc_doo_banner] vc_doo_banner.php:74
[vc_doo_img_banner] vc_doo_banner.php:216
[vc_doo_fashion_banner] vc_doo_banner.php:326
[vc_doo_video_banner] vc_doo_banner.php:468
WordPress Hooks 6
actionadmin_initvc_doo_banner.php:20
actionwp_enqueue_scriptsvc_doo_banner.php:32
actionvc_before_initvc_doo_banner.php:77
actionvc_before_initvc_doo_banner.php:219
actionvc_before_initvc_doo_banner.php:328
actionvc_before_initvc_doo_banner.php:470
Maintenance & Trust

Essential Doo Components for Visual Composer Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedJun 23, 2015
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

Essential Doo Components for Visual Composer Developer Profile

diego.benna

2 plugins · 410 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Essential Doo Components for Visual Composer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/animated-icon-banner-for-visual-composer/vc_doo_banner.css

HTML / DOM Fingerprints

CSS Classes
servicewebsitesvcenter-parentvcentericontitledescription
Data Attributes
data-vc-field-optiondata-vc-field-option-typedata-vc-field-option-headingdata-vc-field-option-valuedata-vc-field-option-descriptiondata-vc-field-option-param_name+2 more
JS Globals
vc
Shortcode Output
<a class="service websites"
FAQ

Frequently Asked Questions about Essential Doo Components for Visual Composer