DragDropr – Visual Drag & Drop Page Builder Security & Risk Analysis

wordpress.org/plugins/dragdropr

DragDropr is a What-You-See-Is-What-You-REALLY-Get visual editor.

20 active installs v1.0.4 PHP + WP 4.4+ Updated Nov 19, 2019
drag-and-dropeditorelementorlanding-pagepage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DragDropr – Visual Drag & Drop Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

DragDropr – Visual Drag & Drop Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The dragdropr plugin v1.0.4 presents a mixed security picture. On the positive side, the static analysis reveals a remarkably small attack surface with zero identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. This is a strong indication of good initial design practices from a security perspective. Furthermore, the plugin has no recorded vulnerability history, suggesting a well-maintained codebase or a lack of past exploitable issues. The absence of dangerous functions and file operations is also a positive sign.

However, several critical concerns emerge from the code analysis. The single SQL query is not using prepared statements, posing a significant risk of SQL injection. While the attack surface is zero, the lack of capability checks and nonce checks on any potential (even if currently zero) entry points is a concern, as it implies a lack of fundamental security measures. The output escaping rate is worryingly low at 37%, meaning a substantial portion of user-facing output is vulnerable to cross-site scripting (XSS) attacks. The taint analysis, while not finding critical or high-severity flows, did identify two flows with unsanitized paths, which could potentially lead to path traversal vulnerabilities if an entry point were ever introduced.

In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the presence of raw SQL queries, poor output escaping, and the absence of fundamental security checks like capability and nonce checks represent substantial security weaknesses that require immediate attention. These flaws, if exploited, could lead to serious security breaches.

Key Concerns

  • SQL queries not using prepared statements
  • Low output escaping rate (37%)
  • No nonce checks
  • No capability checks
  • Taint flows with unsanitized paths
Vulnerabilities
None known

DragDropr – Visual Drag & Drop Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DragDropr – Visual Drag & Drop Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
24
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

37% escaped38 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ddr_rest_oauth1_profile_save (ddr_admin.php:544)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DragDropr – Visual Drag & Drop Page Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 35
actioninitddr-oauth-server.php:44
actioninitddr-oauth-server.php:65
filterdetermine_current_userddr-oauth-server.php:77
filterrest_authentication_errorsddr-oauth-server.php:78
actioninitddr-oauth-server.php:80
actioninitddr-oauth-server.php:102
actiontemplate_redirectddr-oauth-server.php:143
filterrest_indexddr-oauth-server.php:164
actioninitddr-oauth-server.php:176
actionadmin_menuddr_admin.php:9
actionpersonal_optionsddr_admin.php:11
actionall_admin_noticesddr_admin.php:13
actionpersonal_options_updateddr_admin.php:15
actionedit_user_profile_updateddr_admin.php:16
actionedit_form_after_titleddr_admin.php:18
filterpage_row_actionsddr_admin.php:20
filterpost_row_actionsddr_admin.php:21
actionrest_api_initddr_admin.php:23
actionrest_api_initddr_admin.php:79
actionrest_api_initddr_admin.php:105
actionrest_api_initddr_admin.php:153
actionrest_api_initddr_admin.php:201
actionrest_api_initddr_admin.php:250
actionrest_api_initddr_admin.php:300
actionrest_api_initddr_admin.php:330
actionrest_api_initddr_admin.php:398
actionrest_api_initddr_admin.php:448
actionrest_api_initddr_admin.php:485
actionadmin_initddr_admin.php:909
actionadmin_enqueue_scriptsddr_admin.php:912
actionadmin_print_footer_scriptsddr_admin.php:915
actionadmin_enqueue_scriptsddr_admin.php:918
actionadmin_initddr_admin.php:921
filtermce_buttonsddr_admin.php:942
filtermce_external_pluginsddr_admin.php:943
Maintenance & Trust

DragDropr – Visual Drag & Drop Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedNov 19, 2019
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

DragDropr – Visual Drag & Drop Page Builder Developer Profile

dragdropr

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DragDropr – Visual Drag & Drop Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/oauth1/request/wp-json/oauth1/authorize/wp-json/oauth1/access
FAQ

Frequently Asked Questions about DragDropr – Visual Drag & Drop Page Builder