Essential Doo Components for Visual Composer Security & Risk Analysis
wordpress.org/plugins/animated-icon-banner-for-visual-composerEssential Doo Components is the original addon built for Visual Composer which helps you add interactive overlay effects on the sections displayed on …
Is Essential Doo Components for Visual Composer Safe to Use in 2026?
Use With Caution
Score 63/100Essential Doo Components for Visual Composer has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'animated-icon-banner-for-visual-composer' v1.9 presents a mixed security profile. On one hand, the static analysis shows commendable practices regarding SQL query sanitization and output escaping, with 100% of analyzed outputs being properly escaped and all SQL queries utilizing prepared statements. The plugin also lacks external HTTP requests and file operations, which generally reduces its attack surface.
However, significant concerns arise from the vulnerability history. The presence of one unpatched medium severity vulnerability, specifically Cross-Site Scripting (XSS), dating from August 18, 2025, is a major red flag. The lack of any nonce checks or capability checks across all entry points (shortcodes in this case) further amplifies the risk associated with the known XSS vulnerability, as unauthorized or less privileged users could potentially exploit it if not properly mitigated by the WordPress core or theme.
In conclusion, while the code exhibits good practices in specific areas like data sanitization, the unpatched XSS vulnerability and the absence of robust authentication checks on its shortcodes are critical weaknesses. Users are strongly advised to update the plugin to a patched version if available, or to exercise extreme caution and consider disabling it until the vulnerability is addressed.
Key Concerns
- Unpatched medium severity CVE (XSS)
- No nonce checks on shortcodes
- No capability checks on shortcodes
Essential Doo Components for Visual Composer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Essential Doo Components for Visual Composer <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Doo Components for Visual Composer Release Timeline
Essential Doo Components for Visual Composer Code Analysis
Essential Doo Components for Visual Composer Attack Surface
Shortcodes 4
WordPress Hooks 6
Maintenance & Trust
Essential Doo Components for Visual Composer Maintenance & Trust
Maintenance Signals
Community Trust
Essential Doo Components for Visual Composer Alternatives
Carousel, Recent Post Slider and Banner Slider
spice-post-slider
Display your blog posts with a responsive, customizable slider that works smoothly on all devices.
Banner Management, Product Slider, Product Carousel for WooCommerce
banner-management-for-woocommerce
Allows you to set single or multiple banners on the WooCommerce category and page.
Advanced Bootstrap Carousel
advanced-bootstrap-carousel
Advanced Bootstrap Carousel is a light weighted responsive slider plugin.
Jssor Slider by jssor.com
jssor-slider
Responsive Touch Slideshow/Slider/Gallery/Carousel/Banner
Post Slider
posts-slider
Create beautiful and elegant posts sliders easily in minutes. Supports Default & Custom post types.
Essential Doo Components for Visual Composer Developer Profile
2 plugins · 410 total installs
How We Detect Essential Doo Components for Visual Composer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/animated-icon-banner-for-visual-composer/vc_doo_banner.cssHTML / DOM Fingerprints
servicewebsitesvcenter-parentvcentericontitledescriptiondata-vc-field-optiondata-vc-field-option-typedata-vc-field-option-headingdata-vc-field-option-valuedata-vc-field-option-descriptiondata-vc-field-option-param_name+2 morevc<a class="service websites"