BuildABand Security & Risk Analysis

wordpress.org/plugins/buildaband

BuildABand: A powerful wedding band builder with custom styles, profiles, widths, and finishes.

0 active installs v1.0.0 PHP 7.4+ WP 6.7+ Updated Unknown
band-buildercustomize-ringsjewelry-builderring-designer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuildABand Safe to Use in 2026?

Generally Safe

Score 100/100

BuildABand has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'buildaband' v1.0.0 plugin demonstrates several positive security practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of file operations, external HTTP requests, and bundled libraries further reduces its attack surface. The plugin also implements nonce checks, indicating an awareness of common WordPress security vulnerabilities. However, the static analysis revealed two taint flows with unsanitized paths, which are flagged as high severity. This suggests a potential for insecure handling of user-supplied data, even though no specific vulnerabilities have been recorded in its history. The lack of capability checks on AJAX handlers and the shortcode entry points is a notable concern, as it means any authenticated user, regardless of their role, could potentially trigger these functions. The vulnerability history being clean is a positive sign, but it does not negate the risks identified in the current code analysis, particularly the high-severity taint flows and missing capability checks.

Key Concerns

  • High severity unsanitized taint flows found
  • Missing capability checks on AJAX handlers
  • Missing capability checks on shortcode
Vulnerabilities
None known

BuildABand Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BuildABand Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
14 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped14 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
buildaband_addTocartOrder (templates\band-builder-woo-variant.php:60)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BuildABand Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_buildaband_filter_programtemplates\band-builder-woo-variant.php:22
noprivwp_ajax_buildaband_filter_programtemplates\band-builder-woo-variant.php:23
authwp_ajax_buildaband_addTocartOrdertemplates\band-builder-woo-variant.php:57
noprivwp_ajax_buildaband_addTocartOrdertemplates\band-builder-woo-variant.php:58

Shortcodes 1

[BuildABand] buildaband.php:29
WordPress Hooks 2
actionwp_enqueue_scriptsbuildaband.php:82
actionwp_footerbuildaband.php:110
Maintenance & Trust

BuildABand Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads261

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

BuildABand Developer Profile

belgiumwebnetinc

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BuildABand

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buildaband/assets/css/plugins/bootstrap.min.css/wp-content/plugins/buildaband/assets/fonts/montserrat/montserrat.css/wp-content/plugins/buildaband/assets/css/theme.css/wp-content/plugins/buildaband/assets/css/band-builder.css/wp-content/plugins/buildaband/assets/css/responsive.css/wp-content/plugins/buildaband/assets/js/plugins/bootstrap.bundle.min.js/wp-content/plugins/buildaband/assets/js/theme.js/wp-content/plugins/buildaband/assets/images/BVED_AS_W_4MM.jpg+2 more
Script Paths
/wp-content/plugins/buildaband/assets/js/plugins/bootstrap.bundle.min.js/wp-content/plugins/buildaband/assets/js/theme.js
Version Parameters
buildaband/assets/css/plugins/bootstrap.min.css?ver=buildaband/assets/fonts/montserrat/montserrat.css?ver=buildaband/assets/css/theme.css?ver=buildaband/assets/css/band-builder.css?ver=buildaband/assets/css/responsive.css?ver=

HTML / DOM Fingerprints

CSS Classes
main_band_builder_wrapperband_builder_wrapperbuilder-containerbuilder-img-boxbuilder-filterbuilder-innerbox-filterbuilder-innderboxbuilder-filter-circle-btn
Data Attributes
id="preloader"id="PriceValue"id="AddPButtCart"id="profileSelected"id="selectedMetal"id="selectedColor"+6 more
JS Globals
buildaband_ajaxbuildaband_add_to_cart_ajax
Shortcode Output
<div class="main_band_builder_wrapper"><div class="container"><div class="row band_builder_wrapper"><div class="col-12 col-lg-6 left"><div class="builder-container"><div class="builder-img-box"><img src="
FAQ

Frequently Asked Questions about BuildABand