Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Security & Risk Analysis

wordpress.org/plugins/envision-page-builder

Envision Page Builder makes it easy to create stunning, responsive WordPress websites with custom blocks, templates, animations, and more.

100 active installs v0.21 PHP 7.2+ WP 6.5+ Updated Jan 25, 2026
blockblock-editorgutenberg-blocksgutenberg-page-builderpage-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Safe to Use in 2026?

Generally Safe

Score 100/100

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The envision-page-builder plugin v0.21 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping for all identified outputs are significant strengths. The presence of nonce checks on all AJAX handlers further enhances its security, preventing common cross-site request forgery (CSRF) attacks. The plugin also demonstrates good practice by not performing file operations or making external HTTP requests without apparent sanitization in this analysis, and it does not bundle external libraries, mitigating risks associated with outdated third-party code.

However, the analysis does reveal a potential area of concern: the lack of capability checks on its AJAX handlers. While nonce checks are present, they primarily ensure the request originates from a logged-in user and is intended, but they do not verify if that user has the necessary permissions to perform the action. This could lead to privilege escalation vulnerabilities if the AJAX actions are sensitive and accessible to users who shouldn't be able to trigger them. The vulnerability history also shows a complete lack of past vulnerabilities, which, while positive, could also indicate limited testing or a lack of publicly disclosed issues rather than absolute security. Overall, the plugin has a good foundation but could be improved by implementing robust capability checks for its AJAX endpoints.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
11 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped11 total outputs
Attack Surface

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_evpbDesignLibraryTaxonomiesincludes\DesignLibrary\DesignLibrary.php:14
authwp_ajax_evpbDesignLibraryTemplatesincludes\DesignLibrary\DesignLibrary.php:15
authwp_ajax_evpbDesignLibraryTemplateImportincludes\DesignLibrary\DesignLibrary.php:16
WordPress Hooks 5
filterblock_categories_allenvision-page-builder.php:50
actioninitenvision-page-builder.php:51
actionwp_enqueue_scriptsenvision-page-builder.php:52
actionenqueue_block_assetsenvision-page-builder.php:53
actionenqueue_block_editor_assetsenvision-page-builder.php:54
Maintenance & Trust

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 25, 2026
PHP min version7.2
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Developer Profile

Plugin Envision

5 plugins · 5K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Envision Page Builder – A collection of WordPress Gutenberg blocks & templates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/envision-page-builder/build/script.js/wp-content/plugins/envision-page-builder/public/css/aos.css/wp-content/plugins/envision-page-builder/public/js/aos.js/wp-content/plugins/envision-page-builder/build/script.css/wp-content/plugins/envision-page-builder/build/index.js/wp-content/plugins/envision-page-builder/build/index.css
Script Paths
/wp-content/plugins/envision-page-builder/build/script.js/wp-content/plugins/envision-page-builder/public/js/aos.js/wp-content/plugins/envision-page-builder/build/index.js
Version Parameters
envision-page-builder/style.css?ver=envision-page-builder/script.js?ver=envision-page-builder/script.css?ver=envision-page-builder/index.js?ver=envision-page-builder/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
evb-blocksevb-scriptevb-styleevb-index-scriptevb-index-style
Data Attributes
data-aos
JS Globals
evpbNonceevpbWusulEVPB_VERSIONEVPB_BUILD_URLEVPB_DIR_URL
FAQ

Frequently Asked Questions about Envision Page Builder – A collection of WordPress Gutenberg blocks & templates