Express Add On Security & Risk Analysis

wordpress.org/plugins/express-add-on

Express Add-on for Breakdance website builder, the time saver plugin!

10 active installs v1.4.2 PHP 8.0+ WP 6.0+ Updated Jul 15, 2024
breakdancewhatsapp
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Express Add On Safe to Use in 2026?

Generally Safe

Score 92/100

Express Add On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The express-add-on plugin v1.4.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, unpatched vulnerabilities, or critical/high severity issues in its history is a positive indicator of consistent security development or a lack of targeted attacks. The static analysis reveals no obvious entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, the code adheres to good practices with 100% of SQL queries using prepared statements and a high percentage (97%) of output escaping. This indicates a proactive approach to preventing common web vulnerabilities.

However, the analysis does highlight a few areas that warrant consideration. The presence of file operations and external HTTP requests, while not inherently insecure, can introduce risks if not handled with extreme care regarding user input sanitization and validation. Similarly, while nonce and capability checks are present, their limited count (1 each) in conjunction with file operations and HTTP requests could imply that these critical security mechanisms might not be applied universally across all potentially sensitive operations. The taint analysis reporting zero flows is excellent, but it's crucial to remember that static analysis can have limitations in uncovering all dynamic vulnerabilities, especially those involving complex interactions or external data sources.

In conclusion, express-add-on v1.4.2 appears to be a well-developed plugin with a solid foundation of security practices. Its vulnerability history is spotless, and the static analysis shows a commitment to secure coding standards. The main areas for improvement revolve around ensuring comprehensive application of security checks (nonces, capabilities) for all sensitive operations, especially those involving file system interactions and external API calls, to mitigate any potential latent risks.

Key Concerns

  • Limited nonce checks present
  • Limited capability checks present
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Express Add On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Express Add On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
209 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

97% escaped216 total outputs
Attack Surface

Express Add On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 44
actionvxn_express_load_modulesapp\plugin.php:26
actionvxn_express_load_modulesapp\plugin.php:44
filterlitespeed_buffer_beforeapp\plugin.php:55
actioninitapp\plugin.php:182
filterexcerpt_lengthapp\plugin.php:204
actiontemplate_redirectapp\plugin.php:215
actionvxn_express_loadedmodules\testi\testi-module.php:34
actionbreakdance_after_save_documentmodules\whatsapp\whatsapp-popup.php:25
actioninitmodules\woo\breakdance\dynamic-data\dynamic-fields.php:19
filterwoocommerce_product_data_tabsmodules\woo\woo-marketplace-fields.php:20
actionwoocommerce_product_data_panelsmodules\woo\woo-marketplace-fields.php:21
actionwoocommerce_process_product_metamodules\woo\woo-marketplace-fields.php:22
actionadmin_headmodules\woo\woo-marketplace-fields.php:23
filterwoongkir_api_key_hardcodedmodules\woo\woo.php:71
filterwoocommerce_product_add_to_cart_textmodules\woo\woo.php:121
filterwoocommerce_product_single_add_to_cart_textmodules\woo\woo.php:131
filterwoocommerce_is_purchasablemodules\woo\woo.php:151
actionwp_footermodules\woo\woo.php:159
filterwc_add_to_cart_message_htmlmodules\woo\woo.php:175
filterwoocommerce_add_to_cart_redirectmodules\woo\woo.php:178
filterwoocommerce_add_to_cart_validationmodules\woo\woo.php:186
filterwoocommerce_product_add_to_cart_urlmodules\woo\woo.php:199
filterwoocommerce_sale_flashmodules\woo\woo.php:203
filteruse_block_editor_for_post_typemodules\woo\woo.php:232
actioninitmodules\woo\woo.php:241
actionwoocommerce_archive_descriptionmodules\woo\woo.php:247
actionwoocommerce_product_querymodules\woo\woo.php:495
actionwoocommerce_updated_product_stockmodules\woo\woo.php:531
actionwoocommerce_process_product_metamodules\woo\woo.php:533
actionwoocommerce_save_product_variationmodules\woo\woo.php:535
actionadmin_noticespackages\helper\util.php:469
filtergettextpackages\helper\util.php:646
actionadmin_menupackages\wp\menu-page\menu-pages-builder.php:33
actioninitpackages\wp\post-type\post-types-builder.php:41
actionadmin_initpackages\wp\post-type\post-types-builder.php:60
filterenter_title_herepackages\wp\post-type\post-types-builder.php:117
actionplugins_loadedpackages\_root\handler.php:32
actionvxn_express_modules_loadedpackages\_root\handler.php:54
actionvxn_express_loadedpackages\_root\handler.php:58
actionadmin_menupackages\_root\handler.php:80
actioninitpackages\_root\handler.php:123
actionadd_meta_boxespackages\_root\handler.php:138
actionwp_enqueue_scriptspackages\_root\handler.php:147
actioninitpackages\_root\handler.php:163
Maintenance & Trust

Express Add On Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 15, 2024
PHP min version8.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Express Add On Developer Profile

Akah Subarkah

3 plugins · 10 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Express Add On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/express-add-on/packages/breakdance/assets/js/global.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/global.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-options.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-options.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-settings.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-settings.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-tools.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-tools.css+10 more
Script Paths
/wp-content/plugins/express-add-on/packages/breakdance/assets/js/global.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-options.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-settings.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-tools.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/post-type.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/taxonomy.js+3 more
Version Parameters
express-add-on/packages/breakdance/assets/css/global.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-options.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-settings.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-tools.css?ver=express-add-on/packages/breakdance/assets/css/post-type.css?ver=express-add-on/packages/breakdance/assets/css/taxonomy.css?ver=express-add-on/packages/breakdance/assets/css/metabox.css?ver=express-add-on/packages/breakdance/assets/css/menu-page.css?ver=express-add-on/packages/breakdance/assets/css/shortcode.css?ver=

HTML / DOM Fingerprints

CSS Classes
vxn-express-addon
Data Attributes
data-vxn-express-settings
JS Globals
window._vxn_data_
FAQ

Frequently Asked Questions about Express Add On