
DesignSetGo Security & Risk Analysis
wordpress.org/plugins/designsetgoProfessional WordPress blocks without page builder bloat. 53 blocks + 16 universal extensions that enhance ANY block.
Is DesignSetGo Safe to Use in 2026?
Generally Safe
Score 100/100DesignSetGo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'designsetgo' plugin v2.0.40 demonstrates a generally good security posture, with a high percentage of properly escaped outputs and the exclusive use of prepared statements for SQL queries. The plugin also implements a reasonable number of capability checks and nonce checks, indicating an awareness of common WordPress security practices. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a history of stable and secure development.
However, there are specific areas of concern identified in the static analysis. The presence of 2 AJAX handlers and 21 REST API routes, with 2 REST API routes lacking permission callbacks, introduces potential attack vectors that are not adequately protected. Additionally, the use of the `preg_replace(/e)` function, while only appearing twice, is a known indicator of potential Regular Expression Denial of Service (ReDoS) vulnerabilities or other issues related to its evaluation mode. While taint analysis shows no current issues, the identified unprotected entry points and the use of a potentially dangerous function warrant careful consideration.
In conclusion, 'designsetgo' v2.0.40 has strong foundations in secure coding practices, particularly in data handling and output sanitization. The plugin's clean vulnerability history is a significant positive. The primary risks lie in the exposed REST API endpoints and the presence of the `preg_replace(/e)` function, which require immediate attention to mitigate potential security weaknesses and maintain its otherwise robust security profile.
Key Concerns
- REST API routes without permission callbacks
- Dangerous function: preg_replace(/e)
DesignSetGo Security Vulnerabilities
DesignSetGo Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
DesignSetGo Attack Surface
AJAX Handlers 2
REST API Routes 21
WordPress Hooks 95
Scheduled Events 1
Maintenance & Trust
DesignSetGo Maintenance & Trust
Maintenance Signals
Community Trust
DesignSetGo Alternatives
JetFormBuilder — Dynamic Blocks Form Builder
jetformbuilder
Advanced form builder plugin for Gutenberg. Create forms from the ground up, customize the existing ones, and style them up – all in one editor.
UiCore Animate – Free Animations, Transitions, and Interactions Addon for Elementor & Gutenberg blocks
uicore-animate
UiCore Animate adds page transitions, smooth scroll, and engaging animations to Elementor and Gutenberg blocks, for smoother, engaging experiences.
Visibility Controls for Editor Blocks
visibility-controls-for-editor-blocks
Easily hide or show Gutenberg blocks on mobile, tablet, and desktop devices using customizable breakpoints for responsive design.
Animate Blocks
animate-blocks
Animate Gutenberg blocks plugin for WordPress.
Tabs Block
tabs-block
Tabs Block is a simple plugin that adds a Gutenberg block for adding Tabs content to your posts and pages.
DesignSetGo Developer Profile
1 plugin · 30 total installs
How We Detect DesignSetGo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/designsetgo/build/admin.css/wp-content/plugins/designsetgo/build/admin.js/wp-content/plugins/designsetgo/build/admin.jsdesignsetgo/build/admin.js?ver=designsetgo/build/admin.css?ver=HTML / DOM Fingerprints
designsetgo-admin-appdata-designsetgo-form-builderdesignSetGoAdmin/designsetgo/v1