Cards for Beaver Builder Security & Risk Analysis

wordpress.org/plugins/bb-bootstrap-cards

Cards for Beaver Builder A quick and easy to use plugin to build creative and responsive cards for Beaver Builder. Tags: Cards for Beaver Builder, bea …

1K active installs v1.1.8 PHP + WP 4.4+ Updated Jan 29, 2026
bb-bootstrap-cardsbeaver-buildercards-for-beaver-builderdrag-and-drop-cardspage-builder-plugin
98
A · Safe
CVEs total3
Unpatched0
Last CVEJun 28, 2024
Safety Verdict

Is Cards for Beaver Builder Safe to Use in 2026?

Generally Safe

Score 98/100

Cards for Beaver Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Jun 28, 2024Updated 3mo ago
Risk Assessment

The "bb-bootstrap-cards" plugin, version 1.1.8, exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, SQL queries using prepared statements, file operations, external HTTP requests, or known vulnerabilities in the current version. Furthermore, the plugin has no observed AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a very limited attack surface. However, a significant concern is the low percentage (40%) of properly escaped output. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected and executed as malicious scripts within the browser. The vulnerability history, with three past medium-severity XSS vulnerabilities, reinforces this concern. While these are not currently unpatched, the pattern of past XSS issues coupled with insufficient output escaping in the current version is a red flag. The lack of capability checks and nonce checks on potential entry points, although currently not exposed by the static analysis, could become a risk if future updates introduce new functionalities.

Key Concerns

  • Low output escaping percentage
  • History of XSS vulnerabilities
  • No capability checks
  • No nonce checks
Vulnerabilities
3 published

Cards for Beaver Builder Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-37278medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cards for Beaver Builder <= 1.1.4 - Authenticated (Editor+) Stored Cross-Site Scripting

Jun 28, 2024 Patched in 1.1.5 (5d)
CVE-2024-5663medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cards for Beaver Builder <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Cards Widget

Jun 7, 2024 Patched in 1.1.4 (1d)
CVE-2024-2305medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cards for Beaver Builder <= 1.1.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via bootstrapcard link

Mar 21, 2024 Patched in 1.1.3 (133d)
Version History

Cards for Beaver Builder Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Cards for Beaver Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped81 total outputs
Attack Surface

Cards for Beaver Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitbb-bootstrap-cards.php.php:31
actioninitbb-bootstrap-cards.php.php:32
actionadmin_noticesbb-bootstrap-cards.php.php:50
actionnetwork_admin_noticesbb-bootstrap-cards.php.php:51
Maintenance & Trust

Cards for Beaver Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version
Downloads48K

Community Trust

Rating86/100
Number of ratings4
Active installs1K
Developer Profile

Cards for Beaver Builder Developer Profile

Pratik Chaskar

16 plugins · 14K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
131 days
View full developer profile
Detection Fingerprints

How We Detect Cards for Beaver Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bb-bootstrap-cards/bb-bootstrap-cards-module/bb-bootstrap-cards-module.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Cards for Beaver Builder