
Grid Security & Risk Analysis
wordpress.org/plugins/gridGrid is a containerist landingpage editor.
Is Grid Safe to Use in 2026?
Generally Safe
Score 99/100Grid has a strong security track record. Known vulnerabilities have been patched promptly.
The 'grid' plugin v2.3.2 presents a mixed security posture. While it shows strengths in avoiding dangerous functions, file operations, and critical taint flows, significant concerns exist regarding its entry points and handling of SQL queries and output. The presence of two AJAX handlers without authentication checks creates a considerable attack surface that could be exploited by unauthenticated users. Furthermore, only 11% of SQL queries use prepared statements, and a mere 30% of output is properly escaped, indicating a high risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history, while showing no currently unpatched CVEs, includes one medium-severity vulnerability, which, combined with the static analysis findings, suggests a pattern of potential security weaknesses. The plugin's strengths lie in its lack of bundled libraries and the use of nonces and capability checks on some functionalities, but these are overshadowed by the critical unauthenticated entry points and the poor practices in handling sensitive data operations.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Medium severity vulnerability in history
Grid Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Grid <= 2.3.1 - Cross-Site Request Forgery
Grid Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Grid Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
Grid Maintenance & Trust
Maintenance Signals
Community Trust
Grid Alternatives
Grid Social Boxes
grid-social-boxes
Additional boxes for Grid Plugin
WP Table Tag Gen
wp-table-tag-gen
This plugin generates table tags with simple operations.
Admin Posts Navigation
admin-posts-navigation
Navigate between posts and pages without returning to the post list. Works with Classic Editor, Gutenberg, and all Custom Post Types.
Admin Setting
admin-setting
With Admin Setting you can easily customize the WordPress admin menu and toolbar and customize the admin and login interfaces Admin Setting provides a …
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Grid Developer Profile
22 plugins · 2K total installs
How We Detect Grid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/grid/core/css//wp-content/plugins/grid/core/js//wp-content/plugins/grid/editor/css//wp-content/plugins/grid/editor/js//wp-content/plugins/grid/frontend/css//wp-content/plugins/grid/frontend/js//wp-content/plugins/grid/admin/css//wp-content/plugins/grid/admin/js//wp-content/plugins/grid/core/js/grid.js/wp-content/plugins/grid/editor/js/grid-editor.js/wp-content/plugins/grid/frontend/js/grid-frontend.jsgrid/core/js/grid.js?ver=grid/editor/js/grid-editor.js?ver=grid/frontend/js/grid-frontend.js?ver=grid/core/css/grid.css?ver=grid/editor/css/grid-editor.css?ver=grid/frontend/css/grid-frontend.css?ver=HTML / DOM Fingerprints
grid-editor-containergrid-editor-slotgrid-editor-drag-handlergrid-rowgrid-columngrid-containergrid editor: containergrid editor: slotdata-grid-iddata-grid-container-iddata-grid-slot-iddata-grid-container-classdata-grid-container-styledata-grid-slot-class+1 moregrid_editor_configgrid_frontend_data/wp-json/grid/v1/get_grid//wp-json/grid/v1/save_grid//wp-json/grid/v1/delete_grid//wp-json/grid/v1/get_containers//wp-json/grid/v1/save_container//wp-json/grid/v1/delete_container//wp-json/grid/v1/get_slots//wp-json/grid/v1/save_slot//wp-json/grid/v1/delete_slot/<div class="grid-container<div class="grid-row<div class="grid-column