WPBakery Visual Composer & qTranslate-X Security & Risk Analysis

wordpress.org/plugins/js-composer-qtranslate-x

Enables multilingual framework for plugin "WPBakery Visual Composer".

8K active installs v1.0 PHP + WP 4.0+ Updated Nov 28, 2017
bilinguali18nl10nlanguagemultilingual
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPBakery Visual Composer & qTranslate-X Safe to Use in 2026?

Generally Safe

Score 85/100

WPBakery Visual Composer & qTranslate-X has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of js-composer-qtranslate-x v1.0 reveals an exceptionally clean codebase from a security perspective. The absence of any detected dangerous functions, file operations, external HTTP requests, and the perfect adherence to prepared statements for SQL queries and proper output escaping indicate a strong commitment to secure coding practices. Furthermore, the lack of any identified taint flows with unsanitized paths or critical/high severity issues further bolsters this positive assessment. The plugin also boasts a clean vulnerability history with zero known CVEs, suggesting a well-maintained and secure past. However, the complete lack of any detected entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and could indicate that the plugin's functionality is not exposed through standard WordPress mechanisms, or that the static analysis might have missed these due to the plugin's architecture or how it integrates with other components. While the code itself appears secure, this absence of discernible entry points warrants a slight caution, as it might imply an indirect or less obvious attack vector that wasn't captured.

Vulnerabilities
None known

WPBakery Visual Composer & qTranslate-X Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPBakery Visual Composer & qTranslate-X Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

WPBakery Visual Composer & qTranslate-X Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WPBakery Visual Composer & qTranslate-X Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionqtranslate_init_languagejs-composer-qtranslate-x.php:26
filterqtranslate_load_admin_page_configqvc-admin.php:4
filtervc_frontend_editor_iframe_urlqvc-admin.php:36
Maintenance & Trust

WPBakery Visual Composer & qTranslate-X Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedNov 28, 2017
PHP min version
Downloads150K

Community Trust

Rating64/100
Number of ratings11
Active installs8K
Developer Profile

WPBakery Visual Composer & qTranslate-X Developer Profile

John Clause

2 plugins · 8K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPBakery Visual Composer & qTranslate-X

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
js-composer-qtranslate-x/js-composer-qtranslate-x.php?ver=1.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WPBakery Visual Composer & qTranslate-X