
DragDropr – Visual Drag & Drop Page Builder Security & Risk Analysis
wordpress.org/plugins/dragdroprDragDropr is a What-You-See-Is-What-You-REALLY-Get visual editor.
Is DragDropr – Visual Drag & Drop Page Builder Safe to Use in 2026?
Generally Safe
Score 85/100DragDropr – Visual Drag & Drop Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dragdropr plugin v1.0.4 presents a mixed security picture. On the positive side, the static analysis reveals a remarkably small attack surface with zero identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. This is a strong indication of good initial design practices from a security perspective. Furthermore, the plugin has no recorded vulnerability history, suggesting a well-maintained codebase or a lack of past exploitable issues. The absence of dangerous functions and file operations is also a positive sign.
However, several critical concerns emerge from the code analysis. The single SQL query is not using prepared statements, posing a significant risk of SQL injection. While the attack surface is zero, the lack of capability checks and nonce checks on any potential (even if currently zero) entry points is a concern, as it implies a lack of fundamental security measures. The output escaping rate is worryingly low at 37%, meaning a substantial portion of user-facing output is vulnerable to cross-site scripting (XSS) attacks. The taint analysis, while not finding critical or high-severity flows, did identify two flows with unsanitized paths, which could potentially lead to path traversal vulnerabilities if an entry point were ever introduced.
In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the presence of raw SQL queries, poor output escaping, and the absence of fundamental security checks like capability and nonce checks represent substantial security weaknesses that require immediate attention. These flaws, if exploited, could lead to serious security breaches.
Key Concerns
- SQL queries not using prepared statements
- Low output escaping rate (37%)
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths
DragDropr – Visual Drag & Drop Page Builder Security Vulnerabilities
DragDropr – Visual Drag & Drop Page Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DragDropr – Visual Drag & Drop Page Builder Attack Surface
WordPress Hooks 35
Maintenance & Trust
DragDropr – Visual Drag & Drop Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
DragDropr – Visual Drag & Drop Page Builder Alternatives
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder
templatespare
Imagine this... You’re planning your new website. You’re excited at first—but then reality hits. The design takes months. You wait for the developer t …
Multi-step Forms FREE (for Elementor)
multi-step-forms-free-for-elementor
A simple plugin that streamlines the creation of multistep (or multiple page) forms to an easy drag-and-drop through the power of Elementor Pro.
Page builder for Posts – Mong9 Editor
mong9-editor
The most advanced frontend drag & drop content editor. Mong9 Editor is a responsive page builder which can be used to extend the Classic Editor.
Widgets Testimonial DT
widgets-testimonial-dt
add a block of testimonials to the web page, this plugin needs the previous installation of Elementor
DragDropr – Visual Drag & Drop Page Builder Developer Profile
1 plugin · 20 total installs
How We Detect DragDropr – Visual Drag & Drop Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/wp-json/oauth1/request/wp-json/oauth1/authorize/wp-json/oauth1/access