
Boostify Header Footer Builder for Elementor Security & Risk Analysis
wordpress.org/plugins/boostify-header-footer-builderCreate Header, Footer and Mega menu for your WordPress website using Elementor Page Builder for free.
Is Boostify Header Footer Builder for Elementor Safe to Use in 2026?
Generally Safe
Score 89/100Boostify Header Footer Builder for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The Boostify Header Footer Builder plugin version 1.4.1 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The plugin exposes 13 entry points, with 2 AJAX handlers lacking authentication checks. This is a notable weakness that could allow unauthorized users to trigger potentially sensitive actions. The vulnerability history shows 4 previously disclosed medium-severity vulnerabilities, including authorization bypass and cross-site scripting. The fact that none are currently unpatched is positive, but the recurring nature of these vulnerability types suggests ongoing challenges in secure coding practices within the plugin's development.
While the static analysis did not reveal critical or high-severity taint flows, the presence of unprotected AJAX handlers is a direct risk. The past vulnerabilities, though medium severity, point to a need for more robust authorization and input validation mechanisms. The plugin's strength lies in its SQL query security and output escaping. However, the identified unprotected entry points and historical vulnerability patterns necessitate caution. Overall, while some security fundamentals are in place, the exposed attack surface and past vulnerabilities indicate a moderate risk level that requires attention, particularly from users who may not be actively updating the plugin.
Key Concerns
- 2 unprotected AJAX handlers
- 4 past medium severity CVEs
- Missing capability checks on 2 AJAX handlers
Boostify Header Footer Builder for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Boostify Header Footer Builder for Elementor <= 1.3.6 - Authenticated (Contributor+) Post Disclosure
Boostify Header Footer Builder for Elementor <= 1.3.5 - Missing Authorization to Page/Post Creation
Boostify Header Footer Builder for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via size Parameter
Appsero <= 1.2.1 - Missing Authorization
Boostify Header Footer Builder for Elementor Code Analysis
Output Escaping
Data Flow Analysis
Boostify Header Footer Builder for Elementor Attack Surface
AJAX Handlers 10
Shortcodes 3
WordPress Hooks 39
Maintenance & Trust
Boostify Header Footer Builder for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Boostify Header Footer Builder for Elementor Alternatives
BuildWithGuru Sticky Header & Footer Builder for Elementor
buildwithguru
Create custom headers and footers with Elementor and apply optional sticky behavior on scroll. Lightweight and compatible with most WordPress themes.
Header Footer Builder for Elementor
header-footer-builder-for-elementor
Header Footer Builder for Eelementor for WordPress & WooCommerce. Beginner-friendly, eCommerce-ready, optimized and fully compatible Plugin.
Softtemplates For Elementor
softtemplates-for-elementor
SoftTemplates for Elementor is a plugin that allows you to create a header, footer, blog archive, blog page, search page, single page template and sin …
Site Builder for Elementor
site-builder-for-elementor
An intuitive solution to create custom header/footer for your site with Elementor Page Builder and site elements.
Prime Builder
prime-builder
A theme builder for Elementor — build headers, footers, archive and single templates, and customize theme parts with Elementor.
Boostify Header Footer Builder for Elementor Developer Profile
3 plugins · 59K total installs
How We Detect Boostify Header Footer Builder for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boostify-header-footer-builder/assets/css/admin/admin.css/wp-content/plugins/boostify-header-footer-builder/assets/css/ionicons.css/wp-content/plugins/boostify-header-footer-builder/assets/css/awesome.css/wp-content/plugins/boostify-header-footer-builder/assets/js/admin.js/wp-content/plugins/boostify-header-footer-builder/assets/js/admin-rtl.js/wp-content/plugins/boostify-header-footer-builder/assets/js/admin.js/wp-content/plugins/boostify-header-footer-builder/assets/js/admin-rtl.jsboostify-header-footer-builder/assets/css/admin/admin.css?ver=boostify-header-footer-builder/assets/css/ionicons.css?ver=boostify-header-footer-builder/assets/css/awesome.css?ver=boostify-header-footer-builder/assets/js/admin.js?ver=boostify-header-footer-builder/assets/js/admin-rtl.js?ver=HTML / DOM Fingerprints
boostify-hf-adminbhf-shortcode-col-wrapbhf-large-textbhf-typeboostify-lightboxboostify-templates-modalboostify-dialog-widget-contentboostify-templates-modal__header+19 moredata-post-type='btf_builder'admin[bhf id='' type='