
Fusion Page Builder Security & Risk Analysis
wordpress.org/plugins/fusionFusion. The forever free, natively powerful, beautifully flexible, and easily expandable page builder for Wordpress.
Is Fusion Page Builder Safe to Use in 2026?
Mostly Safe
Score 78/100Fusion Page Builder is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "fusion" plugin v1.6.4 presents a mixed security posture. The static analysis reveals strong adherence to good security practices in several areas. Notably, all identified entry points (AJAX handlers, shortcodes) appear to have authentication checks, there are no raw SQL queries, and a high percentage (90%) of output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests is also positive. Furthermore, the plugin utilizes nonces and capability checks extensively.
However, the plugin's vulnerability history raises significant concerns. With two known CVEs, one of which remains unpatched, there is a clear indication of past security weaknesses that have not been fully remediated. The fact that both historical vulnerabilities are categorized as medium severity and relate to Cross-site Scripting (XSS) suggests a pattern of input sanitization or output encoding issues that attackers have successfully exploited in the past. The lack of critical or high severity vulnerabilities in the historical data, coupled with the static analysis showing few critical taint flows or unsanitized paths, might suggest that past issues were addressable without introducing major new risks, but the unpatched vulnerability is a direct and present danger.
In conclusion, while "fusion" v1.6.4 demonstrates strengths in its current implementation regarding secure coding practices, the presence of an unpatched medium severity vulnerability is a critical weakness. This historical issue suggests a potential for similar vulnerabilities to exist or re-emerge if not thoroughly addressed. Users should be cautious and prioritize updating to a version that resolves the outstanding CVE.
Key Concerns
- Unpatched CVE (medium severity)
- Bundled libraries (Select2 - potential for outdated versions)
Fusion Page Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Fusion <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Fusion <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Fusion Page Builder Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Fusion Page Builder Attack Surface
AJAX Handlers 21
Shortcodes 10
WordPress Hooks 43
Maintenance & Trust
Fusion Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Fusion Page Builder Alternatives
Fusion Page Builder : Extension – Gallery
fusion-extension-gallery
Extend Fusion with a Gallery Element.
Fusion Page Builder : Extension – Image
fusion-extension-image
Extend Fusion with an Image Element.
Fusion Page Builder : Extension – Button
fusion-extension-button
Extend Fusion with a Button Element.
Fusion Page Builder : Extension – Contact Form
fusion-extension-contact-form
Extend Fusion with a Contact Form Element.
Fusion Page Builder : Extension – Divider
fusion-extension-divider
Extend Fusion with a Divider Element.
Fusion Page Builder Developer Profile
14 plugins · 7K total installs
How We Detect Fusion Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fusion/includes/bootstrap/admin/js/bootstrap.min.js/wp-content/plugins/fusion/includes/css/jquery-ui-1.11.4.custom/jquery-ui.min.css/wp-content/plugins/fusion/includes/js/fusion-core-admin.js/wp-content/plugins/fusion/includes/css/fusion-core-admin.css/wp-content/plugins/fusion/includes/js/fusion-core-admin.jsfusion-core-admin.js?ver=fusion-core-admin.css?ver=HTML / DOM Fingerprints
fsn-wrapperdata-fsn-iddata-fsn-typedata-fsn-editdata-fsn-paramsdata-fsn-parent-idfsnJS[fsn_row][/fsn_row][fsn_row_inner][/fsn_row_inner]