JVH VC Templates Essentials Security & Risk Analysis

wordpress.org/plugins/jvh-vc-templates-essentials

This plugin adds the ability to create custom VC Templates for the Essentials theme.

10 active installs v1.1.0 PHP 7.3+ WP 5.0+ Updated Dec 18, 2021
jvh
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is JVH VC Templates Essentials Safe to Use in 2026?

Generally Safe

Score 85/100

JVH VC Templates Essentials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the static analysis, the "jvh-vc-templates-essentials" plugin version 1.1.0 presents a strong security posture. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that lack proper authentication or permission checks. Furthermore, the code signals are largely positive, with no dangerous functions, no direct SQL queries (all use prepared statements), and no file operations or external HTTP requests. This indicates careful development practices and a minimal attack surface.

However, there are a couple of areas that raise minor concerns. The output escaping is not comprehensive, with 33% of outputs potentially unescaped, which could lead to cross-site scripting vulnerabilities if the data originates from user input and is not sufficiently sanitized elsewhere. Additionally, the complete absence of nonce checks and capability checks, while not directly indicating a vulnerability in this version due to the lack of exposed entry points, suggests a potential weakness if new features are added without adhering to these security best practices.

The vulnerability history is completely clean, with no recorded CVEs. This, combined with the positive static analysis, suggests that the plugin has been well-maintained and developed with security in mind. The strengths of this plugin lie in its limited attack surface and the secure handling of database interactions. The primary weakness is the incomplete output escaping, which warrants attention.

Key Concerns

  • Output not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

JVH VC Templates Essentials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

JVH VC Templates Essentials Release Timeline

v1.1.0Current
Code Analysis
Analyzed Mar 17, 2026

JVH VC Templates Essentials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

JVH VC Templates Essentials Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionvc_backend_editor_renderinc\Plugin.php:27
actionadmin_enqueue_scriptsinc\Plugin.php:39
actionvc_backend_editor_renderinc\Plugin.php:43
actioninitinc\Plugin.php:52
actionwp_headinc\Plugin.php:93
actionrestrict_manage_postsinc\Plugin.php:102
actionadmin_initinc\Plugin.php:129
actionvc_load_default_templates_actioninc\Plugin.php:185
actioninitinc\Plugin.php:200
actioninitinc\Plugin.php:228
filtermanage_jvh-vc-template_posts_columnsinc\Plugin.php:247
actionmanage_jvh-vc-template_posts_custom_columninc\Plugin.php:256
filtermanage_jvh-vc-template_posts_columnsinc\Plugin.php:267
Maintenance & Trust

JVH VC Templates Essentials Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 18, 2021
PHP min version7.3
Downloads894

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

JVH VC Templates Essentials Developer Profile

jaapjvh

8 plugins · 470 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JVH VC Templates Essentials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jvh-vc-templates-essentials/assets/js/sort-vc-templates.js/wp-content/plugins/jvh-vc-templates-essentials/assets/js/add-thumbnails-jvh-vc-templates.js/wp-content/plugins/jvh-vc-templates-essentials/assets/css/admin-style.css/wp-content/plugins/jvh-vc-templates-essentials/assets/css/hide-essentials-vc-template.css
Script Paths
/wp-content/plugins/jvh-vc-templates-essentials/assets/js/sort-vc-templates.js/wp-content/plugins/jvh-vc-templates-essentials/assets/js/add-thumbnails-jvh-vc-templates.js
Version Parameters
sort-vc-templates.js?ver=add-thumbnails-jvh-vc-templates.js?ver=

HTML / DOM Fingerprints

CSS Classes
jvh-vc-template
Data Attributes
taxonomy="category-jvh-template"value="category-jvh-template"
JS Globals
jvhTemplateThumbs
FAQ

Frequently Asked Questions about JVH VC Templates Essentials