BCorp Visual Editor Security & Risk Analysis

wordpress.org/plugins/bcorp-visual-editor

Powerful drag and drop page builder.

20 active installs v0.20 PHP + WP 4.2.0+ Updated Mar 22, 2016
buildercomposereditpagepage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BCorp Visual Editor Safe to Use in 2026?

Generally Safe

Score 85/100

BCorp Visual Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The bcorp-visual-editor plugin version 0.20 demonstrates a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a significant positive indicator. Furthermore, the presence of nonce and capability checks on the identified AJAX handler is commendable, indicating an effort to secure entry points. The plugin also shows good practices in output escaping, with a majority of outputs being properly handled.

However, a closer examination reveals potential areas for improvement. While the attack surface is small and the single AJAX handler is protected, there are no REST API routes analyzed, which could represent an overlooked entry point. The taint analysis showing zero flows analyzed means that complex, multi-stage vulnerabilities may not have been detected. The vulnerability history being completely clear is a good sign but doesn't guarantee future security, especially in conjunction with the limited taint analysis.

Overall, the plugin appears to be built with security in mind, adhering to many best practices. The lack of known vulnerabilities and the secure handling of identified entry points are strengths. The primary concern lies in the unknown vulnerabilities that might exist due to the limited taint analysis. Continued vigilance and thorough testing, especially for more complex interaction scenarios, would be beneficial.

Key Concerns

  • 100% of outputs are not properly escaped
  • Taint analysis not performed
Vulnerabilities
None known

BCorp Visual Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BCorp Visual Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Attack Surface

BCorp Visual Editor Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_bcve_ajaxbcorp_visual_editor.php:133
WordPress Hooks 7
actionbcorp_start_visual_editorbcorp_visual_editor.php:14
actionmedia_buttonsbcorp_visual_editor.php:18
actionadmin_enqueue_scriptsbcorp_visual_editor.php:19
actionadmin_menubcorp_visual_editor.php:67
actionadmin_enqueue_scriptsbcorp_visual_editor.php:134
actionedit_form_after_titlebcorp_visual_editor.php:135
actionsave_postbcorp_visual_editor.php:136
Maintenance & Trust

BCorp Visual Editor Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 22, 2016
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

BCorp Visual Editor Developer Profile

BCorp

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BCorp Visual Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bcorp-visual-editor/css/bcorp-visual-editor-admin.css/wp-content/plugins/bcorp-visual-editor/js/bcorp-visual-editor-admin.js/wp-content/plugins/bcorp-visual-editor/css/bcve.css/wp-content/plugins/bcorp-visual-editor/js/bcve.js
Script Paths
/wp-content/plugins/bcorp-visual-editor/js/bcorp-visual-editor-admin.js/wp-content/plugins/bcorp-visual-editor/js/bcve.js
Version Parameters
bcorp-visual-editor/style.css?ver=css/bcve.css?ver=js/bcve.js?ver=

HTML / DOM Fingerprints

CSS Classes
bcorp-visual-editor-button
Data Attributes
id="bcorp-visual-editor-button"id="bcorp-visual-editor-active"id="bcorp-visual-editor"
JS Globals
window.bcorp_installerwindow.bcve
FAQ

Frequently Asked Questions about BCorp Visual Editor