Flexi Post Grid Security & Risk Analysis

wordpress.org/plugins/flexi-post-grid

AJAX-powered Post Grid widget for Elementor with preset layouts, filters, pagination types, and slider support.

90 active installs v1.2.0 PHP 7.4+ WP 5.6+ Updated Mar 14, 2026
blog-gridelementor-gridevent-gridpost-sliderproduct-grid
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flexi Post Grid Safe to Use in 2026?

Generally Safe

Score 100/100

Flexi Post Grid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The flexi-post-grid v1.2.0 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output suggests good practices in preventing cross-site scripting vulnerabilities. The presence of nonce and capability checks on entry points, coupled with the lack of any recorded vulnerabilities or CVEs, indicates a mature and secure development process. The attack surface is also well-managed, with all identified AJAX handlers reportedly having authentication checks. Taint analysis showing zero flows, especially critical or high severity ones, further reinforces this positive assessment. However, a very minor concern arises from the limited number of nonce and capability checks (2 and 1 respectively) relative to the 4 AJAX handlers. While the analysis states these are protected, this ratio could be reviewed for absolute robustness. Overall, this plugin appears to be a secure choice with a history of responsible development and a well-defended codebase.

Vulnerabilities
None known

Flexi Post Grid Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flexi Post Grid Release Timeline

v1.2.0Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Flexi Post Grid Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
213 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped218 total outputs
Attack Surface

Flexi Post Grid Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_flexipostgridbuilder_load_postsajax-handler.php:5
noprivwp_ajax_flexipostgridbuilder_load_postsajax-handler.php:6
authwp_ajax_flexipostgridbuilder_fetch_categoriesajax-handler.php:624
noprivwp_ajax_flexipostgridbuilder_fetch_categoriesajax-handler.php:625
WordPress Hooks 15
actionwp_enqueue_scriptsflexipostgridbuilder.php:114
actionelementor/frontend/after_enqueue_scriptsflexipostgridbuilder.php:115
actionelementor/editor/after_enqueue_scriptsflexipostgridbuilder.php:116
actionelementor/editor/before_enqueue_scriptsflexipostgridbuilder.php:122
actionadmin_enqueue_scriptsflexipostgridbuilder.php:138
actionelementor/editor/after_enqueue_scriptsflexipostgridbuilder.php:155
actionelementor/widgets/registerflexipostgridbuilder.php:175
actionadmin_noticesflexipostgridbuilder.php:205
actionelementor/elements/categories_registeredflexipostgridbuilder.php:228
actionwp_enqueue_scriptsflexipostgridbuilder.php:269
actionelementor/editor/after_enqueue_scriptsflexipostgridbuilder.php:285
actionadmin_menuflexipostgridbuilder.php:291
actionadmin_enqueue_scriptsflexipostgridbuilder.php:320
actionadmin_initflexipostgridbuilder.php:377
filterexcerpt_moreflexipostgridbuilder.php:402
Maintenance & Trust

Flexi Post Grid Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads745

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Flexi Post Grid Developer Profile

creativewebui

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flexi Post Grid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flexi-post-grid/assets/style.css/wp-content/plugins/flexi-post-grid/assets/blog-grid-filter.js/wp-content/plugins/flexi-post-grid/assets/admin-style.css/wp-content/plugins/flexi-post-grid/assets/reset-controls.js
Script Paths
/wp-content/plugins/flexi-post-grid/assets/blog-grid-filter.js/wp-content/plugins/flexi-post-grid/assets/reset-controls.js
Version Parameters
flexi-post-grid/assets/style.css?ver=flexi-post-grid/assets/blog-grid-filter.js?ver=flexi-post-grid/assets/admin-style.css?ver=flexi-post-grid/assets/reset-controls.js?ver=

HTML / DOM Fingerprints

CSS Classes
flexi-post-grid
HTML Comments
<!-- Placeholder image (path + URL) --><!-- Free/Pro flags (Free build stays false; Pro build can set true) --><!-- Core paths/URLs (used across the plugin) --><!-- Plugin Name: Flexi Post Grid -->+9 more
Data Attributes
data-elementor-iddata-elementor-post-typedata-elementor-typedata-elementor-device-mode
JS Globals
flexipostgridbuilder_paramsflexipostgridbuilder_frontend
Shortcode Output
[flexi-post-grid[flexi_post_grid
FAQ

Frequently Asked Questions about Flexi Post Grid