
Classic Addons – WPBakery Page Builder Security & Risk Analysis
wordpress.org/plugins/classic-addons-wpbakery-page-builder-addons15+ Beautiful and Powerful Addons for WPBakery Page Builder (Visual Composer)
Is Classic Addons – WPBakery Page Builder Safe to Use in 2026?
Generally Safe
Score 96/100Classic Addons – WPBakery Page Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of Classic Addons WP Bakery Page Builder Addons v3.7 shows a generally strong security posture with several good practices in place. The plugin boasts a high percentage of properly escaped outputs and utilizes prepared statements exclusively for SQL queries, which significantly mitigates common vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Furthermore, the fact that all identified entry points have at least one nonce check is a positive sign, indicating an effort to prevent CSRF attacks.
However, a significant concern arises from the plugin's vulnerability history. With a total of three known CVEs, two of which are high severity, and past instances of critical vulnerabilities like Remote File Inclusion and Path Traversal, this indicates a recurring pattern of security weaknesses. The presence of Cross-Site Scripting as a common vulnerability type, even if not explicitly flagged in the current static analysis, is concerning given the past issues.
While the current version (v3.7) shows no unpatched vulnerabilities and a clean taint analysis, the historical context cannot be ignored. The plugin has a history of critical security flaws, suggesting a need for more robust and consistent security practices. The lack of capability checks on its single AJAX handler, coupled with the past vulnerabilities, presents a potential risk if the AJAX handler processes user input without proper authorization, even if current taint analysis shows no issues. This history warrants careful monitoring and a cautious approach to its deployment.
Key Concerns
- Historical high-severity vulnerabilities (2)
- Historical medium-severity vulnerability (1)
- Lack of capability checks on AJAX handler
- Past Cross-site Scripting vulnerabilities
Classic Addons – WPBakery Page Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Editor+) Local File Inclusion
Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion
Classic Addons – WPBakery Page Builder <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Classic Addons – WPBakery Page Builder Code Analysis
Output Escaping
Data Flow Analysis
Classic Addons – WPBakery Page Builder Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Classic Addons – WPBakery Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Classic Addons – WPBakery Page Builder Alternatives
WPBakery Page Builder Addons by Livemesh
addons-for-visual-composer
A collection of 25+ beautifully designed premium quality addons or extensions for WPBakery Page Builder.
ChargeWP Timeline Addons For WPBakery Page Builder
chargewp-timeline-addons-for-wpbakery
Power your WPBakery Page Builder with well crafted timeline addons.
Social Elements for WPBakery Page Builder
social-elements-for-wpbakery
A collection of social elements (share buttons, profile links, and more) for WPBakery Page Builder.
HT Mega – Absolute Addons for WPBakery Page Builder
ht-mega-for-wpbakery
The HTMega is a WPBakery Page builder addons package for WPBakery Page Builder plugin for WordPress.
Web and WooCommerce Addons for WPBakery Builder
vc-addons-by-bit14
Clean, responsive, well designed addons for WPBakery Page Builder with custom post type
Classic Addons – WPBakery Page Builder Developer Profile
4 plugins · 5K total installs
How We Detect Classic Addons – WPBakery Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.css/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.css/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.js/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.jsclassic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.css?ver=classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js?ver=classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.css?ver=classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.js?ver=HTML / DOM Fingerprints
caw-alert-boxcaw-style-top-iconcaw-dismissiblecaw-alert-closecaw-alert-contentcaw-alert-titlecaw-aheadingdata-dismiss-target<div id="caw-alert-<button type="button" class="caw-alert-close"<div class="caw-alert-content"><h3 class="caw-alert-title