Boostify Header Footer Builder for Elementor Security & Risk Analysis

wordpress.org/plugins/boostify-header-footer-builder

Create Header, Footer and Mega menu for your WordPress website using Elementor Page Builder for free.

9K active installs v1.4.1 PHP + WP 5.8+ Updated Mar 4, 2025
elementorelementor-headerfooter-builderheader-buildersticky-menu
89
A · Safe
CVEs total4
Unpatched0
Last CVENov 12, 2024
Safety Verdict

Is Boostify Header Footer Builder for Elementor Safe to Use in 2026?

Generally Safe

Score 89/100

Boostify Header Footer Builder for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Nov 12, 2024Updated 1yr ago
Risk Assessment

The Boostify Header Footer Builder plugin version 1.4.1 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The plugin exposes 13 entry points, with 2 AJAX handlers lacking authentication checks. This is a notable weakness that could allow unauthorized users to trigger potentially sensitive actions. The vulnerability history shows 4 previously disclosed medium-severity vulnerabilities, including authorization bypass and cross-site scripting. The fact that none are currently unpatched is positive, but the recurring nature of these vulnerability types suggests ongoing challenges in secure coding practices within the plugin's development.

While the static analysis did not reveal critical or high-severity taint flows, the presence of unprotected AJAX handlers is a direct risk. The past vulnerabilities, though medium severity, point to a need for more robust authorization and input validation mechanisms. The plugin's strength lies in its SQL query security and output escaping. However, the identified unprotected entry points and historical vulnerability patterns necessitate caution. Overall, while some security fundamentals are in place, the exposed attack surface and past vulnerabilities indicate a moderate risk level that requires attention, particularly from users who may not be actively updating the plugin.

Key Concerns

  • 2 unprotected AJAX handlers
  • 4 past medium severity CVEs
  • Missing capability checks on 2 AJAX handlers
Vulnerabilities
4

Boostify Header Footer Builder for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
3 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2024-10794medium · 4.3Authorization Bypass Through User-Controlled Key

Boostify Header Footer Builder for Elementor <= 1.3.6 - Authenticated (Contributor+) Post Disclosure

Nov 12, 2024 Patched in 1.3.7 (1d)
CVE-2024-4788medium · 4.3Missing Authorization

Boostify Header Footer Builder for Elementor <= 1.3.5 - Missing Authorization to Page/Post Creation

Jun 5, 2024 Patched in 1.3.6 (28d)
CVE-2024-5006medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Boostify Header Footer Builder for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via size Parameter

Jun 4, 2024 Patched in 1.3.3 (1d)

Appsero <= 1.2.1 - Missing Authorization

Dec 16, 2022 Patched in 1.2.9 (699d)
Code Analysis
Analyzed Mar 16, 2026

Boostify Header Footer Builder for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
208 escaped
Nonce Checks
8
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped256 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
boostify_hf_input (inc\admin\class-metabox.php:427)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Boostify Header Footer Builder for Elementor Attack Surface

Entry Points13
Unprotected2

AJAX Handlers 10

authwp_ajax_boostify_create_postinc\admin\class-admin.php:36
authwp_ajax_boostify_hf_load_autocomplateinc\admin\class-metabox.php:34
authwp_ajax_boostify_hf_post_admininc\admin\class-metabox.php:35
authwp_ajax_bhf_more_ruleinc\admin\class-metabox.php:36
authwp_ajax_boostify_hf_ex_autoinc\admin\class-metabox.php:37
authwp_ajax_boostify_hf_typeinc\admin\class-metabox.php:38
authwp_ajax_boostify_product_removeinc\elementor\module\class-woocommerce.php:39
noprivwp_ajax_boostify_product_removeinc\elementor\module\class-woocommerce.php:40
authwp_ajax_boostify_ajax_add_to_cartinc\elementor\module\class-woocommerce.php:41
noprivwp_ajax_boostify_ajax_add_to_cartinc\elementor\module\class-woocommerce.php:42

Shortcodes 3

[btf_year] inc\class-boostify-header-footer-builder.php:73
[btf_site_tile] inc\class-boostify-header-footer-builder.php:74
[bhf] inc\elementor\class-template-render.php:39
WordPress Hooks 39
actionadmin_enqueue_scriptsinc\admin\class-admin.php:32
filtermanage_btf_builder_posts_columnsinc\admin\class-admin.php:33
actionmanage_btf_builder_posts_custom_columninc\admin\class-admin.php:34
actionadmin_footerinc\admin\class-admin.php:35
actionadd_meta_boxesinc\admin\class-metabox.php:32
actionsave_postinc\admin\class-metabox.php:33
actioninitinc\class-boostify-header-footer-builder.php:64
actioninitinc\class-boostify-header-footer-builder.php:65
actionplugins_loadedinc\class-boostify-header-footer-builder.php:66
actionbody_classinc\class-boostify-header-footer-builder.php:67
actionelementor/editor/wp_headinc\class-boostify-header-footer-builder.php:68
actionwp_enqueue_scriptsinc\class-boostify-header-footer-builder.php:69
actionwp_enqueue_scriptsinc\class-boostify-header-footer-builder.php:70
actionboostify_hf_seach_forminc\class-boostify-header-footer-builder.php:71
actionadmin_noticesinc\class-boostify-header-footer-builder.php:72
actionwpinc\class-template.php:56
actionwp_headinc\class-template.php:57
filtersingle_templateinc\class-template.php:58
actionboostify_hf_get_headerinc\class-template.php:60
actionboostify_hf_get_footerinc\class-template.php:62
actionget_headerinc\class-template.php:70
actionget_footerinc\class-template.php:71
actionelementor/initinc\elementor\class-elementor.php:256
actionelementor/initinc\elementor\class-elementor.php:257
actionelementor/elements/categories_registeredinc\elementor\class-elementor.php:259
actionelementor/frontend/after_register_scriptsinc\elementor\class-elementor.php:261
actionelementor/widgets/registerinc\elementor\class-elementor.php:263
actionelementor/initinc\elementor\class-elementor.php:264
actionelementor/controls/controls_registeredinc\elementor\class-elementor.php:265
actionwp_enqueue_scriptsinc\elementor\class-template-render.php:38
actionelementor/element/section/section_advanced/after_section_endinc\elementor\module\class-sticky.php:234
actionelementor/element/common/section_advanced/after_section_startinc\elementor\module\class-sticky.php:235
actionelementor/frontend/after_enqueue_stylesinc\elementor\module\class-sticky.php:236
actionwp_enqueue_scriptsinc\elementor\module\class-sticky.php:237
filteradd_to_cart_fragmentsinc\elementor\module\class-woocommerce.php:34
actionelementor/editor/before_enqueue_scriptsinc\elementor\module\class-woocommerce.php:35
actioninitinc\elementor\module\class-woocommerce.php:37
actioninitinc\menu\class-wp-sub-menu.php:31
filterwp_nav_menu_objectsinc\menu\class-wp-sub-menu.php:39
Maintenance & Trust

Boostify Header Footer Builder for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 4, 2025
PHP min version
Downloads113K

Community Trust

Rating72/100
Number of ratings9
Active installs9K
Developer Profile

Boostify Header Footer Builder for Elementor Developer Profile

Dylan Ngo - Woostify

3 plugins · 59K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
366 days
View full developer profile
Detection Fingerprints

How We Detect Boostify Header Footer Builder for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/boostify-header-footer-builder/assets/css/admin/admin.css/wp-content/plugins/boostify-header-footer-builder/assets/css/ionicons.css/wp-content/plugins/boostify-header-footer-builder/assets/css/awesome.css/wp-content/plugins/boostify-header-footer-builder/assets/js/admin.js/wp-content/plugins/boostify-header-footer-builder/assets/js/admin-rtl.js
Script Paths
/wp-content/plugins/boostify-header-footer-builder/assets/js/admin.js/wp-content/plugins/boostify-header-footer-builder/assets/js/admin-rtl.js
Version Parameters
boostify-header-footer-builder/assets/css/admin/admin.css?ver=boostify-header-footer-builder/assets/css/ionicons.css?ver=boostify-header-footer-builder/assets/css/awesome.css?ver=boostify-header-footer-builder/assets/js/admin.js?ver=boostify-header-footer-builder/assets/js/admin-rtl.js?ver=

HTML / DOM Fingerprints

CSS Classes
boostify-hf-adminbhf-shortcode-col-wrapbhf-large-textbhf-typeboostify-lightboxboostify-templates-modalboostify-dialog-widget-contentboostify-templates-modal__header+19 more
Data Attributes
data-post-type='btf_builder'
JS Globals
admin
Shortcode Output
[bhf id='' type='
FAQ

Frequently Asked Questions about Boostify Header Footer Builder for Elementor