
Bricksable for Bricks Builder Security & Risk Analysis
wordpress.org/plugins/bricksableElevate your website game with the Bricksable collection of premium elements for Bricks Builder. Designed to speed up your workflow, our customizable …
Is Bricksable for Bricks Builder Safe to Use in 2026?
Generally Safe
Score 99/100Bricksable for Bricks Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of Bricksable v1.6.83 indicates a generally good security posture with no identified entry points lacking authentication or permission checks. The plugin demonstrates strong practices by using prepared statements for all SQL queries and implementing nonce and capability checks on its internal functions. File operations are notably absent, and there are no critical or high-severity taint flows identified, suggesting a low risk of direct code execution or sensitive data compromise through these channels.
However, a concerning aspect is the output escaping. With 79% of outputs properly escaped, there is still a significant percentage (21%) that are not. This creates a potential attack vector for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of a medium-severity XSS vulnerability. The single external HTTP request also warrants scrutiny, as it could be a potential avenue for various attacks if not handled securely. The presence of a past vulnerability, even if patched, indicates that the plugin has had security weaknesses in the past.
In conclusion, while Bricksable v1.6.83 benefits from robust input validation and SQL handling, the incomplete output escaping remains a notable weakness that could lead to XSS attacks. The plugin's history, though currently clear of unpatched vulnerabilities, highlights the importance of continued vigilance. Developers should prioritize addressing the unescaped outputs to mitigate the risk of XSS and ensure all external requests are handled with maximum security precautions.
Key Concerns
- Unescaped output percentage is 21%
- Past medium severity XSS vulnerability
- One external HTTP request
Bricksable for Bricks Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bricksable for Bricks Builder <= 1.6.59 - Authenticated (Administrator+) Stored Cross-Site Scripting
Bricksable for Bricks Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bricksable for Bricks Builder Attack Surface
WordPress Hooks 23
Maintenance & Trust
Bricksable for Bricks Builder Maintenance & Trust
Maintenance Signals
Community Trust
Bricksable for Bricks Builder Alternatives
Bricks Navigator
brickslabs-bricks-navigator
Adds quick links in the WordPress admin bar for users of Bricks theme.
Max Addons for Bricks Builder
max-addons-for-bricks
Maximise your website building experience with the collection of useful and creative elements for Bricks Builder
Webhook for Bricks Forms
webhook-for-bricks-forms
Adds form ID and webhook URL pairs to trigger specific webhooks on Bricks form submissions, with debug options.
Yabe Ukiyo
yabe-ukiyo
Bricks remote templates manager.
Bricksed Mobile & Mega Menu for Bricks Builder
bricksed
Mobile Menu and Mega menu element for Bricks Builder that enhances your WordPress navigation with advanced features and mobile-friendly design.
Bricksable for Bricks Builder Developer Profile
1 plugin · 10K total installs
How We Detect Bricksable for Bricks Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bricksable/assets/css/bricksable.css/wp-content/plugins/bricksable/assets/js/bricksable.js/wp-content/plugins/bricksable/assets/js/bricksable-elementor.js/wp-content/plugins/bricksable/assets/css/bricksable-elementor.css/wp-content/plugins/bricksable/assets/js/bricksable-migration.js/wp-content/plugins/bricksable/assets/js/bricksable-review.js/wp-content/plugins/bricksable/assets/js/bricksable-admin-api.js/wp-content/plugins/bricksable/assets/js/bricksable-post-type.js+1 more/wp-content/plugins/bricksable/assets/js/bricksable.js/wp-content/plugins/bricksable/assets/js/bricksable-elementor.js/wp-content/plugins/bricksable/assets/js/bricksable-migration.js/wp-content/plugins/bricksable/assets/js/bricksable-review.js/wp-content/plugins/bricksable/assets/js/bricksable-admin-api.js/wp-content/plugins/bricksable/assets/js/bricksable-post-type.js+1 morebricksable/assets/css/bricksable.css?ver=bricksable/assets/js/bricksable.js?ver=bricksable/assets/js/bricksable-elementor.js?ver=bricksable/assets/css/bricksable-elementor.css?ver=bricksable/assets/js/bricksable-migration.js?ver=bricksable/assets/js/bricksable-review.js?ver=bricksable/assets/js/bricksable-admin-api.js?ver=bricksable/assets/js/bricksable-post-type.js?ver=bricksable/assets/js/bricksable-taxonomy.js?ver=HTML / DOM Fingerprints
bricksable-containerbricksable-section-wrapbricksable-column-wrapbricksable-element<!-- Bricksable element --><!-- Bricksable container --><!-- Bricksable section wrap --><!-- Bricksable column wrap -->data-bricksable-elementdata-bricksable-containerdata-bricksable-section-wrapdata-bricksable-column-wrapbricksable_editor_settingsbricksable_elements_databricksable_pro_active/wp-json/bricksable/v1/settings/wp-json/bricksable/v1/elements[bricksable_accordion][bricksable_tabs][bricksable_slider]