
Jemdy Product Builder Security & Risk Analysis
wordpress.org/plugins/jemdy-product-builderCreate a modern WooCommerce product builder with attribute/price filters and variation support. Shortcode: [jemdy-builder-form].
Is Jemdy Product Builder Safe to Use in 2026?
Generally Safe
Score 100/100Jemdy Product Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jemdy-product-builder" plugin v2.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively, and has a very high rate of output escaping. The absence of file operations, external HTTP requests, and known vulnerabilities in its history are also positive indicators of a generally well-developed plugin. However, significant concerns arise from its attack surface. With three total entry points, two of which lack authentication checks, and zero nonce checks, the plugin exposes potentially sensitive functionalities to unauthenticated users. This, coupled with a single capability check across all code, suggests a significant risk of unauthorized access or manipulation if these unprotected entry points can be leveraged for malicious purposes.
The static analysis indicates two AJAX handlers are exposed without authentication, which is a critical oversight. While taint analysis found no issues, this could be due to the limited scope of analysis or the nature of the code. The absence of nonce checks on AJAX handlers, in particular, is a common vector for Cross-Site Request Forgery (CSRF) attacks. The plugin's vulnerability history is clean, which is encouraging, but does not mitigate the immediate risks identified in the current code analysis. The plugin has strengths in data handling and output sanitization, but its unprotected entry points represent a substantial security weakness that requires immediate attention.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- Large attack surface without auth checks
- Low capability check coverage
Jemdy Product Builder Security Vulnerabilities
Jemdy Product Builder Code Analysis
SQL Query Safety
Output Escaping
Jemdy Product Builder Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Jemdy Product Builder Maintenance & Trust
Maintenance Signals
Community Trust
Jemdy Product Builder Alternatives
Visual Product Configurator for Woocommerce Lite
visual-products-configurator-for-woocommerce
A woocommerce product customizer for woocommerce that allows customers to build any composite product visually.
WCB | WP Configurator Builder – Product Configurators Made Simple
wcb-configurator-builder
Create customizable products with ease; custom product fields, real-time updates, stackable image layers, and more!
Custom Product Builder or Configurator for WooCommerce
wpappsdev-pcbuilder
Product Builder or Configurator: Complete PC Components Selling Solution For WooCommerce.
CPB – Custom Product Builder for WooCommerce
cpb-custom-product-builder
Advanced product customization solution with drag-and-drop builder interface. Requires active WooCommerce.com subscription.
Custom Product Configurator for WooCommerce
custom-product-configurator-for-woocommerce
Create ready-to-sell product configurators in WooCommerce using one-click templates. No complex setup, no spreadsheets, no emails.
Jemdy Product Builder Developer Profile
1 plugin · 0 total installs
How We Detect Jemdy Product Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jemdy-product-builder/assets/dist/jemdy-product-builder/block-builder-form.js/wp-content/plugins/jemdy-product-builder/assets/dist/jemdy-product-builder/page-manager.jshttp://localhost:3000/block-builder-form.tsxhttp://localhost:3000/page-manager.tsxjemdy-product-builder/assets/dist/jemdy-product-builder/block-builder-form.js?ver=jemdy-product-builder/assets/dist/jemdy-product-builder/page-manager.js?ver=HTML / DOM Fingerprints
type="module"window.$RefreshReg$window.$RefreshSig$window.__vite_plugin_react_preamble_installed__window.jdpb[jemdy-builder-form]