
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Security & Risk Analysis
wordpress.org/plugins/gym-builderGymBuilder simplifies gym management with class schedules,trainer profiles,fitness calculators,member management,and shortcode generators.
Is Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Safe to Use in 2026?
Generally Safe
Score 100/100Gym Builder – Fitness, Gym, Class Schedule Maker Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gym-builder' plugin v2.3.1 exhibits a generally good security posture, with a high percentage of SQL queries using prepared statements and proper output escaping. The plugin also demonstrates a strong adherence to nonces and capability checks, indicating an awareness of common WordPress security best practices. Its lack of any recorded vulnerabilities or CVEs further bolsters confidence in its current security state.
However, the analysis reveals several areas of concern. A significant portion of the attack surface, specifically 6 out of 14 AJAX handlers and 1 out of 4 REST API routes, lacks proper authentication or permission checks. This presents a considerable risk, as unauthenticated or unauthorized users could potentially trigger these endpoints, leading to unintended actions or information disclosure. Additionally, the presence of the `unserialize` function, even if not immediately flagged by taint analysis in this specific version, is a known dangerous function that can lead to deserialization vulnerabilities if not handled with extreme care and proper input validation.
In conclusion, while the plugin benefits from a clean vulnerability history and strong implementation of core security features like prepared statements and output escaping, the unprotected entry points in its AJAX handlers and REST API are a notable weakness. The presence of `unserialize` also warrants caution. Developers should prioritize addressing the unprotected AJAX and REST API endpoints to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Presence of dangerous function (unserialize)
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Security Vulnerabilities
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Attack Surface
AJAX Handlers 14
REST API Routes 4
Shortcodes 4
WordPress Hooks 94
Maintenance & Trust
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Alternatives
fitness calculators
fitness-calculators
Plugin for calculating Water intake, BMI calculator, protein Intake for the fitness freaks.
fitnessbliss calculators plugin
fitnessbliss-calculators
Plugin for calculating Water intake, BMI calculator, protein Intake for the fitness freaks.
Human BMI Calculator
human-bmi-calculator
Human BMI (Body Mass Index) Calculator will help you to check your current BMI for your height and weight.
WP Calorie Calculator
wp-calorie-calculator
For all experts in fitness, health & calories-dependent nutrition or sports: meet the most effective marketing feature for your WordPress website!
CC BMI Calculator
cc-bmi-calculator
Add a free simple customizable BMI Calculator to your web site.
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin Developer Profile
2 plugins · 180 total installs
How We Detect Gym Builder – Fitness, Gym, Class Schedule Maker Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gym-builder/assets/admin/images/100x100-logo.pngHTML / DOM Fingerprints
gym_builder-offer-noticegym_builder_offerdata-gym_builderdismissablegym_builder__notice