
Express Add On Security & Risk Analysis
wordpress.org/plugins/express-add-onExpress Add-on for Breakdance website builder, the time saver plugin!
Is Express Add On Safe to Use in 2026?
Generally Safe
Score 92/100Express Add On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The express-add-on plugin v1.4.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, unpatched vulnerabilities, or critical/high severity issues in its history is a positive indicator of consistent security development or a lack of targeted attacks. The static analysis reveals no obvious entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, the code adheres to good practices with 100% of SQL queries using prepared statements and a high percentage (97%) of output escaping. This indicates a proactive approach to preventing common web vulnerabilities.
However, the analysis does highlight a few areas that warrant consideration. The presence of file operations and external HTTP requests, while not inherently insecure, can introduce risks if not handled with extreme care regarding user input sanitization and validation. Similarly, while nonce and capability checks are present, their limited count (1 each) in conjunction with file operations and HTTP requests could imply that these critical security mechanisms might not be applied universally across all potentially sensitive operations. The taint analysis reporting zero flows is excellent, but it's crucial to remember that static analysis can have limitations in uncovering all dynamic vulnerabilities, especially those involving complex interactions or external data sources.
In conclusion, express-add-on v1.4.2 appears to be a well-developed plugin with a solid foundation of security practices. Its vulnerability history is spotless, and the static analysis shows a commitment to secure coding standards. The main areas for improvement revolve around ensuring comprehensive application of security checks (nonces, capabilities) for all sensitive operations, especially those involving file system interactions and external API calls, to mitigate any potential latent risks.
Key Concerns
- Limited nonce checks present
- Limited capability checks present
- File operations present
- External HTTP requests present
Express Add On Security Vulnerabilities
Express Add On Code Analysis
Output Escaping
Express Add On Attack Surface
WordPress Hooks 44
Maintenance & Trust
Express Add On Maintenance & Trust
Maintenance Signals
Community Trust
Express Add On Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
Express Add On Developer Profile
3 plugins · 10 total installs
How We Detect Express Add On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/express-add-on/packages/breakdance/assets/js/global.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/global.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-options.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-options.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-settings.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-settings.css/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-tools.js/wp-content/plugins/express-add-on/packages/breakdance/assets/css/breakdance-tools.css+10 more/wp-content/plugins/express-add-on/packages/breakdance/assets/js/global.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-options.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-settings.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/breakdance-tools.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/post-type.js/wp-content/plugins/express-add-on/packages/breakdance/assets/js/taxonomy.js+3 moreexpress-add-on/packages/breakdance/assets/css/global.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-options.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-settings.css?ver=express-add-on/packages/breakdance/assets/css/breakdance-tools.css?ver=express-add-on/packages/breakdance/assets/css/post-type.css?ver=express-add-on/packages/breakdance/assets/css/taxonomy.css?ver=express-add-on/packages/breakdance/assets/css/metabox.css?ver=express-add-on/packages/breakdance/assets/css/menu-page.css?ver=express-add-on/packages/breakdance/assets/css/shortcode.css?ver=HTML / DOM Fingerprints
vxn-express-addondata-vxn-express-settingswindow._vxn_data_