
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Security & Risk Analysis
wordpress.org/plugins/ghostkitCreate engaging websites using over 25 advanced blocks featuring motion effects, smooth animations, and robust extensions.
Is Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Safe to Use in 2026?
Generally Safe
Score 97/100Ghost Kit – Page Builder Blocks, Motion Effects & Extensions has a strong security track record. Known vulnerabilities have been patched promptly.
Ghostkit v3.5.1 exhibits a generally positive security posture, with strong adherence to several best practices. The plugin demonstrates excellent SQL query sanitization, utilizing prepared statements exclusively, and a high percentage of properly escaped output. The limited attack surface, with only one AJAX handler and no unprotected entry points, is also a positive indicator. Furthermore, the presence of numerous capability checks suggests an effort to restrict access to sensitive functionality.
However, the static analysis reveals some areas of concern. Two flows with unsanitized paths were identified, which, despite not being classified as critical or high severity in the taint analysis, could potentially lead to local file inclusion vulnerabilities if the input is not properly validated downstream. The plugin's history of Common Vulnerabilities and Exposures (CVEs), particularly those related to Cross-site Scripting and PHP Remote File Inclusion, is a significant red flag. Although there are currently no unpatched CVEs, the recurring nature of these vulnerability types indicates a persistent risk and suggests that thorough security reviews and input sanitization across all user-controllable data points are crucial.
In conclusion, Ghostkit v3.5.1 benefits from robust SQL handling and a contained attack surface. Nevertheless, the identified unsanitized paths and the historical prevalence of critical vulnerability types like XSS and RFI warrant careful consideration. While the current version appears to have addressed past vulnerabilities, the plugin's history suggests a need for ongoing vigilance and rigorous testing to ensure that new vulnerabilities are not introduced.
Key Concerns
- Unsanitized paths in taint analysis
- Past vulnerabilities: XSS and RFI
- Only 2 nonce checks for 1 AJAX handler
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Ghost Kit <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ghost Kit <= 3.4.1 - Unauthenticated Local File Inclusion
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Code Analysis
Output Escaping
Data Flow Analysis
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Attack Surface
AJAX Handlers 1
WordPress Hooks 103
Maintenance & Trust
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Maintenance & Trust
Maintenance Signals
Community Trust
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Alternatives
Greenshift – animation and page builder blocks
greenshift-animation-and-page-builder-blocks
More than 20 special blocks for Gutenberg to build complex pages and animations with highest possible web vitals score.
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions Developer Profile
90 plugins · 2.1M total installs
How We Detect Ghost Kit – Page Builder Blocks, Motion Effects & Extensions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ghostkit/build/gutenberg/editor.css/wp-content/plugins/ghostkit/build/gutenberg/style.css/wp-content/plugins/ghostkit/build/blocks.js/wp-content/plugins/ghostkit/build/gutenberg/editor.js/wp-content/plugins/ghostkit/build/blocks.asset.php/wp-content/plugins/ghostkit/build/gutenberg/editor.asset.php/wp-content/plugins/ghostkit/gutenberg/classes/class-helper.php/wp-content/plugins/ghostkit/classes/class-assets.php/wp-content/plugins/ghostkit/build/blocks.js/wp-content/plugins/ghostkit/build/gutenberg/editor.jsghostkit/build/gutenberg/style.css?ver=ghostkit/build/gutenberg/editor.css?ver=ghostkit/build/blocks.js?ver=ghostkit/build/gutenberg/editor.js?ver=HTML / DOM Fingerprints
ghostkit-block-countdowndata-ghostkit-block-typeghostkitGhostKit/wp-json/ghostkit/