
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Security & Risk Analysis
wordpress.org/plugins/envision-page-builderEnvision Page Builder makes it easy to create stunning, responsive WordPress websites with custom blocks, templates, animations, and more.
Is Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Safe to Use in 2026?
Generally Safe
Score 100/100Envision Page Builder – A collection of WordPress Gutenberg blocks & templates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The envision-page-builder plugin v0.21 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping for all identified outputs are significant strengths. The presence of nonce checks on all AJAX handlers further enhances its security, preventing common cross-site request forgery (CSRF) attacks. The plugin also demonstrates good practice by not performing file operations or making external HTTP requests without apparent sanitization in this analysis, and it does not bundle external libraries, mitigating risks associated with outdated third-party code.
However, the analysis does reveal a potential area of concern: the lack of capability checks on its AJAX handlers. While nonce checks are present, they primarily ensure the request originates from a logged-in user and is intended, but they do not verify if that user has the necessary permissions to perform the action. This could lead to privilege escalation vulnerabilities if the AJAX actions are sensitive and accessible to users who shouldn't be able to trigger them. The vulnerability history also shows a complete lack of past vulnerabilities, which, while positive, could also indicate limited testing or a lack of publicly disclosed issues rather than absolute security. Overall, the plugin has a good foundation but could be improved by implementing robust capability checks for its AJAX endpoints.
Key Concerns
- Missing capability checks on AJAX handlers
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Security Vulnerabilities
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Code Analysis
SQL Query Safety
Output Escaping
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Maintenance & Trust
Maintenance Signals
Community Trust
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Alternatives
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
blockart-blocks
Enhance the power of your WordPress editor with the dynamic Gutenberg blocks by BlockArt Blocks. Build any layout imaginable.
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
the-plus-addons-for-block-editor
90+ Gutenberg Blocks & AI Website Builder with 1000+ Templates. Complete Page Builder, Popup Builder, Mega Menu, Form Builder & More. No Code.
Kenta Blocks – Responsive Blocks and block templates library
kenta-blocks
Kenta Blocks is a set of responsive blocks with powerful options and pre-designed templates library.
Grids: Layout builder for WordPress
grids
The most advanced page and layout builder for Gutenberg and the new Block Editor, with columns, rows and responsive controls.
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates Developer Profile
5 plugins · 5K total installs
How We Detect Envision Page Builder – A collection of WordPress Gutenberg blocks & templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envision-page-builder/build/script.js/wp-content/plugins/envision-page-builder/public/css/aos.css/wp-content/plugins/envision-page-builder/public/js/aos.js/wp-content/plugins/envision-page-builder/build/script.css/wp-content/plugins/envision-page-builder/build/index.js/wp-content/plugins/envision-page-builder/build/index.css/wp-content/plugins/envision-page-builder/build/script.js/wp-content/plugins/envision-page-builder/public/js/aos.js/wp-content/plugins/envision-page-builder/build/index.jsenvision-page-builder/style.css?ver=envision-page-builder/script.js?ver=envision-page-builder/script.css?ver=envision-page-builder/index.js?ver=envision-page-builder/index.css?ver=HTML / DOM Fingerprints
evb-blocksevb-scriptevb-styleevb-index-scriptevb-index-styledata-aosevpbNonceevpbWusulEVPB_VERSIONEVPB_BUILD_URLEVPB_DIR_URL