
Cards for Beaver Builder Security & Risk Analysis
wordpress.org/plugins/bb-bootstrap-cardsCards for Beaver Builder A quick and easy to use plugin to build creative and responsive cards for Beaver Builder. Tags: Cards for Beaver Builder, bea …
Is Cards for Beaver Builder Safe to Use in 2026?
Generally Safe
Score 98/100Cards for Beaver Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bb-bootstrap-cards" plugin, version 1.1.8, exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, SQL queries using prepared statements, file operations, external HTTP requests, or known vulnerabilities in the current version. Furthermore, the plugin has no observed AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a very limited attack surface. However, a significant concern is the low percentage (40%) of properly escaped output. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected and executed as malicious scripts within the browser. The vulnerability history, with three past medium-severity XSS vulnerabilities, reinforces this concern. While these are not currently unpatched, the pattern of past XSS issues coupled with insufficient output escaping in the current version is a red flag. The lack of capability checks and nonce checks on potential entry points, although currently not exposed by the static analysis, could become a risk if future updates introduce new functionalities.
Key Concerns
- Low output escaping percentage
- History of XSS vulnerabilities
- No capability checks
- No nonce checks
Cards for Beaver Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Cards for Beaver Builder <= 1.1.4 - Authenticated (Editor+) Stored Cross-Site Scripting
Cards for Beaver Builder <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Cards Widget
Cards for Beaver Builder <= 1.1.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via bootstrapcard link
Cards for Beaver Builder Release Timeline
Cards for Beaver Builder Code Analysis
Output Escaping
Cards for Beaver Builder Attack Surface
WordPress Hooks 4
Maintenance & Trust
Cards for Beaver Builder Maintenance & Trust
Maintenance Signals
Community Trust
Cards for Beaver Builder Alternatives
Timed Content For Beaver Builder
timed-content-for-beaver-builder
A very easy to use plugin to hide content automatically after given time. Its purely PHP based plugin, so it removes content from source as well.
Expandable Row for Beaver Builder
expandable-row-for-beaver-builder
Simple Expandable Row for Beaver Builder.
Alerts for Beaver Builder
bb-bootstrap-alerts
Url: https://wordpress.org/plugins/bb-bootstrap-alerts/ Suggestion: https://wordpress.org/plugins/beaver-builder-alerts/ Alerts for Beaver Builder An …
Column Separator for Beaver Builder
column-separator-for-beaver-builder
Column separator for Beaver Builder.
Beaver Builder Page Builder – Drag and Drop Website Builder
beaver-builder-lite-version
The Professional's Choice for Drag & Drop WordPress Page Building. Fast, Reliable, and Trusted since 2014.
Cards for Beaver Builder Developer Profile
16 plugins · 14K total installs
How We Detect Cards for Beaver Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bb-bootstrap-cards/bb-bootstrap-cards-module/bb-bootstrap-cards-module.php